Enterprise technology doesn’t move forward through product announcements alone. It also changes through the conversations that challenge familiar assumptions, introduce a different way of looking at an established problem, or give leaders a clearer view of what’s coming next.

The Q2 2026 EM360Tech Impact Index recognises the content, experts and organisations that created this kind of meaningful impact across the enterprise technology landscape.

The Vanguard Award celebrates the quarter’s most innovative and forward-thinking podcast. It isn’t based on audience size, campaign performance or the scale of the company involved. Instead, it recognises a conversation that brought a valuable new perspective to an issue enterprise leaders can’t afford to ignore.

em360tech image

For Q2 2026, that winner is Zafran Security for its The Security Strategist episode, Are Security Teams Wasting Resources on 99% of Vulnerabilities That Don't Matter?

The conversation stood out because it didn't treat agentic AI as another feature being added to the cybersecurity stack. Instead, it asked what happens when security teams begin trusting intelligent systems to interpret exposure, weigh risk and help decide what should happen next.

The Conversation Behind the Win

The winning episode brought together Zafran Security CISO Nathan Rollings and The Security Strategist host Richard Stiennon, Chief Research Analyst at IT-Harvest.

Their discussion focused on the evolution from traditional vulnerability management to continuous threat exposure management, often shortened to CTEM, and then towards what Zafran describes as agentic exposure management.

Traditional vulnerability management usually begins with scanning systems for known weaknesses. Those findings are then scored, prioritised and sent to the people responsible for fixing them. The process sounds straightforward until thousands of vulnerabilities start competing for attention across a large enterprise environment.

CTEM builds on that process by continuously evaluating which weaknesses could create a genuine path to attack. Instead of looking at a vulnerability in isolation, it considers factors such as whether the affected system is connected to the internet, whether the vulnerable software is running and which security controls already stand between an attacker and the asset.

Agentic exposure management takes another step. Rather than simply presenting this information to a person, AI agents can help interpret it, identify ownership, support threat analysis and coordinate parts of the response.

As Rollings explained, the underlying work hasn’t necessarily changed. Security teams still need to detect vulnerabilities, understand their potential impact and decide how to respond. What’s changing is how much manual input those processes require.

The central question was no longer whether AI could produce another risk score or dashboard. It was whether AI agents could help security teams act on the context already spread across their tools and environments.

Why the Topic Mattered

Enterprise security teams have spent years collecting more vulnerability data. The harder problem has been deciding which parts of that data deserve immediate action. A vulnerability scanner may identify tens of thousands of weaknesses across an organisation. 

Yet each finding exists within a specific technical environment, surrounded by firewalls, endpoint protections, network controls and application configurations that can either increase or reduce the real risk.

When those factors aren’t considered properly, teams can spend months working through ticket queues without knowing whether they’re fixing the exposures attackers are most likely to use. Rollings cited Zafran research suggesting that only one in 50,000 vulnerabilities is truly exploitable once the surrounding context is taken into account. 

That figure reflects Zafran’s analysis rather than an industry-wide rule, but the wider point is difficult to dismiss. A vulnerability’s severity score doesn’t tell a security team whether an attacker can actually reach and exploit it inside their environment. That distinction becomes more important as attacks accelerate.

https://em360tech.com/podcasts/stop-fixing-99-percent-vulnerabilities-that-dont-matter-zafran 

Security teams aren’t only dealing with a growing number of weaknesses. They’re also facing attackers that can use automation and AI to research targets, identify openings and adapt their methods more quickly. A defensive process built around static reports, manual investigation and long remediation queues will struggle to match that pace.

The cost isn’t limited to cyber risk. Every unnecessary patch, investigation and escalation also consumes time that technical teams could spend supporting the business. When prioritisation is weak, vulnerability management can become an expensive cycle of activity without a clear connection to reduced exposure.

Where the Conversation Moved Beyond the Expected

Agentic AI discussions often fall into one of two predictable camps. Either the technology is presented as an inevitable replacement for human work, or the risks are treated as a reason to keep autonomous systems away from sensitive decisions entirely. The Zafran conversation took a more practical route.

Rollings didn’t argue that AI agents were ready to replace vulnerability management teams. Instead, he described a shift in what those teams could spend their time doing. Tasks such as identifying asset owners, validating possible false positives, gathering data from different tools and analysing the impact of a patch can require hours of manual work. 

Automating parts of that process gives practitioners more room to investigate threats that would otherwise remain buried beneath routine administration. That’s a more useful way to think about the technology. The immediate value of agentic security isn’t fewer people. It’s fewer wasted decisions.

The episode also challenged the assumption that stronger AI code analysis will eventually remove the need for exposure management. During the discussion, Stiennon raised Anthropic’s move into AI-assisted code security and the possibility that powerful models could disrupt parts of the application security market. 

Rollings drew an important distinction between finding flaws in source code and understanding risk inside a live enterprise environment. Code analysis can show that a weakness exists. It can’t, on its own, account for every network route, endpoint policy, security rule, runtime condition or compensating control surrounding the deployed system.

That operational picture requires information from across the security stack. A platform may need to understand data from firewalls, endpoint detection tools, cloud services, identity systems and network controls before it can judge whether a vulnerability creates a realistic attack path.

Are you enjoying the content so far?

The discussion therefore moved beyond the familiar idea that AI’s role is simply to find more flaws. The deeper opportunity is using AI to understand how those flaws interact with the environment around them.

The Enterprise Takeaway

Security leaders don’t need to hand full control of their environments to autonomous agents overnight. They do need to reconsider how much of their current exposure management process depends on people manually joining information together. The starting point is visibility across existing controls.

Organisations already invest heavily in firewalls, endpoint protection, intrusion prevention, segmentation and other defensive technologies. Yet those tools are often assessed separately. Security teams may know which products have been deployed without having a clear view of how they work together to reduce the risk attached to a specific exposure.

That makes interoperability more than a technical convenience. It becomes part of the organisation’s ability to make sound security decisions. CISOs should expect exposure management platforms to use telemetry from the tools already operating across their environments. 

They should also ask vendors how AI is being applied, what evidence supports its recommendations and which actions still require human approval. Trust can’t be treated as a switch that’s either on or off. It has to be built through defined boundaries, transparent reasoning and evidence that the system behaves safely within the organisation’s own infrastructure.

IMAGE 2

Alt text: 

For some teams, that may begin with AI supporting analysis while people retain full decision-making authority. Others may allow agents to handle low-risk workflows, such as routing findings or gathering evidence, before expanding into remediation planning. The goal isn’t autonomy for its own sake. 

It’s a security process that helps teams concentrate on exposures that could genuinely affect the business.

Final Thoughts: The Role of the Vanguard Award in the Impact Index

The Vanguard Award holds a distinct place within the Q2 2026 EM360Tech Impact Index. Other awards recognise different forms of enterprise impact, from leadership and authority to measurable momentum and industry influence. Vanguard focuses on the point where a conversation begins to change how a familiar problem is understood.

Zafran Security earned that recognition by moving the exposure management discussion beyond scanning, scoring and ticket creation. The podcast treated AI agents as part of a wider shift in security decision-making, where operational context becomes just as important as the vulnerability itself.

Future Vanguard winners won’t necessarily explore the same technologies or reach the same conclusions. Their value will come from identifying the assumptions that no longer fit the reality enterprise leaders are dealing with. As AI becomes more involved in security operations, the questions will continue to change. The most useful conversations will be the ones willing to change with them.