Horizon3.ai’s Stephen Gates on Autonomous Security Testing for Agencies

Horizon3.ai’s Stephen Gates on Autonomous Security Testing for Agencies

  • Horizon3.ai Principal Security SME Stephen Gates has discussed autonomous testing 
  • Gates highlights NodeZero’s ability to test networks using real attack tactics
  • NodeZero is designed to run safely in production environments

Stephen Gates, a principal security subject matter expert at Horizon3.ai, said autonomous, proactive security testing could help government agencies identify and prioritize the risks that pose the greatest threat.

In an article published on Carahsoft.com, Gates wrote that scanning tools could surface thousands of potential vulnerabilities, but agencies often struggle to know which of those weaknesses an attacker could actually exploit.

How Does Pentesting Help Agencies?

Gates explained that penetration testing, or pentesting, could show where an attacker might enter a network and where they could move next, helping agencies prioritize risk based on impact.

He noted that traditional pentesting methods have limitations. According to Gates, older approaches typically rely on a single point-in-time test that produces a snapshot, which could grow outdated quickly. He added that time, budget and staffing constraints could limit the scope of those tests, and results could vary depending on the methodology or personnel involved.

The Horizon3.ai executive stated that agencies need continuous validation rather than periodic assessments to understand which risks remain exploitable in their environments.

What Is NodeZero?

According to Gates, NodeZero is Horizon3.ai’s autonomous, proactive security platform that could take a different approach to pentesting by carrying out real attacks using the same tactics attackers use.

He wrote that the platform could first attempt to gain access to a network, then move laterally, escalate privileges through stolen credentials and locate sensitive data.

Gates added that NodeZero could run safely in production environments during normal business hours and could operate at scale across tens of thousands of endpoints.

He said the platform could give security teams insight into what to fix and how to fix it. Once an issue has been remediated, teams could rerun NodeZero to confirm the fix worked and the vulnerability could no longer be exploited.

Gates noted that no two environments are identical, and each changes constantly as software, hardware and personnel shift over time. He stated that the difference between a vulnerable and an exploitable risk is significant, and NodeZero could give agencies clarity to act on real threats through a continuous cycle of testing, fixing and verification.

Sponsor

Related Articles

Executive Interviews