Agentic AI
,
Artificial Intelligence & Machine Learning
,
Governance & Risk Management
Forescout’s Rik Ferguson on AI-Driven Vulnerability Risks and Visibility Gaps
Anthropic’s Claude Mythos marks a shift in artificial intelligence-driven vulnerability discovery, but the bigger challenge facing defenders is how to respond. Faster exploit development is exposing gaps in asset visibility, patching and security operations across IT and operational technology environments, said Rik Ferguson, vice president of security intelligence at Forescout.
See Also: Reduce Data Exposure and Modernize Financial Security with AI
Emerging AI bug finding means organizations now face a faster cycle of vulnerability identification and exploit development, compressing the time available to respond. That’s a major problem, Ferguson said, because the industry has long struggled with acting on vulnerabilities rather than finding them.
“Finding more vulnerabilities doesn’t solve that problem, and actually makes that problem significantly worse,” Ferguson said.
The threat is even more acute in environments where visibility is limited. OT, IoT and medical device systems often lack strong asset tracking and can’t be patched easily, leaving gaps that attackers can exploit. “You need to move that needle first. Otherwise, the threat data is all for nothing,” he said.
In this video interview with ISMG, Ferguson also discussed:
- How AI technology will accelerate vulnerability discovery and exploit development;
- Why asset visibility remains a critical gap across IT and OT environments;
- What security leaders must prioritize to improve response and resilience.
Ferguson leads security intelligence at Forescout and is also a special adviser to Europol’s European Cyber Crime Centre, a multi-award-winning producer and writer, and a fellow of the Royal Society of Arts. Prior to joining Forescout in 2022, he was vice president of security research at Trend Micro for 15 years. He is qualified as a Certified Ethical Hacker, Certified Information Systems Security Professional and an Information Systems Security Architecture Professional.

