Turbo Talks · Session recap
Why Traditional ASM and CTEM Tools Will Fail in the Next 12 Months
Bikash set the terms before the first slide: "Most of this is two numbers, and I would like us to do the arithmetic together rather than have you take my word for it." The two numbers are half a cent and $300.
Three key highlights
- After a normal vendor margin, a daily ASM or CTEM subscription has half a cent to eleven cents to spend testing each asset. Move to weekly and it is still cents.
- An attacker with AI spends a few hundred dollars per attempt against the same asset. The reasoning that cost $10,000 per application is now 20 to 50 times cheaper at the same depth.
- The answer is not to buy more breadth. It is to pay commodity prices for coverage and move the difference into depth, on the assets that matter.
About the speaker
Bikash Barai is a serial cybersecurity entrepreneur with multiple exits and the Founder and CEO of FireCompass, an AI company building agents for penetration testing. He holds multiple patents in cybersecurity, speaks regularly at RSA, Interop and TED, and has been recognised in Fortune's 40 Under 40.
Watch the session
CISO executive summary
The argument in one line. The price of a tool tells you what the tool can do. At a cent per asset per day, ASM and CTEM products can discover and score exposures. They cannot prove them, because proof costs what reasoning costs.
Key findings
- Two hundred assets under daily monitoring is 73,000 asset-assessments a year. Priced at $1,000 to $20,000 a year, that is 1.4 to 27 cents per asset per test. After a normal 60 percent vendor margin, 0.5 to 11 cents is left to run it. A weekly cadence gives you 4 to 77 cents. Still cents.
- A $10,000 US manual penetration test bought five days of someone who reads business logic, tests authorization boundaries including IDOR, BOLA and privilege escalation, and chains three low-rated findings into one path. Because of that price, it ran on about 20 percent of the surface, once a year.
- FireCompass's AI agents reached #1 OWASP Injection, #1 Up and Comers and #2 Highest Critical Reputation on the US HackerOne business leaderboards, filing 204 reports on about $5,000 a month all-in. The reasoning that cost $10,000 per application now costs a few hundred dollars in tokens, 20 to 50 times cheaper, at the same depth.
- That leaves half a cent of defensive spend against $300 of attacker spend, on every asset you own, every day. A ratio of 60,000 to 1.
Recommendations
- Pay commodity prices for breadth and move the difference into depth. Automated discovery already solves coverage. Coverage is not where the money should go.
- Test at the attacker's price. A few hundred dollars per application, with proof of exploit for every finding. Deepest on P1, on demand for P2, event-driven for P3.
- Put triggers before schedules. A new asset, a new API, a deploy or a disclosed CVE fires a test. Then a cadence by criticality: P1 monthly or on change, P2 quarterly, P3 as events demand.
What this assumes
Bikash's forecast, not a finding: that pricing moves to consumption-based models the way cloud did, because continuous deep testing at current token costs is unaffordable.
Half a cent
Take 200 internet-facing assets under daily monitoring. That is 73,000 asset-assessments a year.
Now take the price. Entry-level third-party risk and ASM products start near $1,000 a year. Better ones sit around $20,000. Divide, and you get 1.4 to 27 cents per asset per test.
Then subtract what the vendor keeps. At a normal 60 percent gross margin, which says nothing about net margin once sales and administrative costs are paid, what is left to actually run the test is 0.5 to 11 cents per asset per day.
The obvious escape is that nobody really scans daily. He closed it on the same slide. Move to a weekly cadence and the budget per test rises to 4 to 77 cents. Still cents.
What depth used to cost
The comparison point is a real penetration test. Ten thousand dollars. Five days. One application. One human who could reason.
That bought a week of someone who reads business logic, tests authorization boundaries including IDOR, BOLA and privilege escalation, and chains three low-rated findings into a single path. It is the work scanners do not do.
And because it cost $10,000, everyone rationed it: the three applications that fit the budget, about 20 percent of the surface, once a year. His point about the other side of the trade is the one usually missed. Attackers rationed it too. Human depth was reserved for targets worth a week of effort.
What $5,000 a month buys now
FireCompass set a budget and ran the experiment on live HackerOne programmes. About $5,000 a month all-in, AI tokens and cloud included. The agents filed 204 reports. In his slide's words, no human wrote the exploits.
The results: number one on OWASP Injection, number one in Up and Comers, and number two for Highest Critical Reputation, on the US HackerOne business leaderboards. On HackerOne you only score by reporting a vulnerability before every other researcher on the platform.
The line that matters for a budget conversation is the conversion. The reasoning that cost $10,000 per application now costs a few hundred dollars in tokens. Twenty to fifty times cheaper, at the same depth.
He was direct about the caveat. This did not come from picking up a model and pointing it at a target. FireCompass built its own small language models, used frontier models alongside them, and developed what he called complex harness engineering and agentic architecture, on around $30 million raised. The point is not that it is easy. It is that the capability now exists at that price.
Everything on the last slide is now in the attacker's hands. Same models. Same token prices. Fewer rules.Bikash Barai
He framed the consequence as a divide rather than an event. The digital divide separated organisations that could compute from those that could not, and it compounded every year because the leaders kept reinvesting. His argument is that the AI divide does the same thing for reasoning, and that the attacker is already on the far side, with depth at a few hundred dollars per attempt, against every asset, on their timeline.
What accumulates on the wrong side of that line he calls depth debt: exposures discovered and scored, never proven.
0.5¢ versus $300
This is the whole talk on one slide, and the definitions matter more than the gap.
| 0.5¢ | $300 | |
|---|---|---|
| What it is | What your ASM or CTEM tool spends testing each asset, each day | What an attacker with AI spends breaking each asset, each attempt |
| What it buys | Enumeration, fingerprinting, CVE matching and a score | Reading business logic, testing authorization, chaining findings and proving the exploit |
Sixty thousand to one. On every asset you own, every day.
Five sessions remain in this series, every Thursday through 22 October. Twenty minutes each, live. Register free
"But ASM was never a pentest." Correct. That is the point.
Bikash put the objection on a slide and agreed with it, which is the most useful move in the session.
ASM was built for asset discovery. It was never meant to be a penetration test. His argument is that this is not a defence of the category, it is a description of its price ceiling. The price tells you what the product can be. A cent per asset per day buys enumeration and fingerprinting. It cannot buy validation, because validation costs what reasoning costs: hundreds of dollars, not cents.
Relabelled as CTEM, it borrows the one word it cannot afford.Bikash Barai
He anchored that on the framework itself. Validation is the fourth of the five CTEM stages, as Gartner defined them in July 2022, and on his reading a discovery-priced tool cannot fund that stage. If you are renewing a tool that calls itself CTEM, that is the question to put to the vendor: which of the five stages does this price actually cover.
Match the attacker's economics, not everything
His recommendation is not more budget. It is a different allocation of the budget you already have.
Breadth times depth times continuity. Maximum on all three is not viable for anyone, the attacker included. Business criticality decides where depth and continuity go.
| Axis | What it answers | What he recommends |
|---|---|---|
| Breadth | How many assets we cover | Solved by automated discovery. Pay commodity prices for it and move the difference into depth |
| Depth | How thoroughly each is tested | Test at the attacker's price: a few hundred dollars per application, proof of exploit for every finding. Deepest on P1, on demand for P2, event-driven for P3. Business logic and multi-stage chains, not CVE matches |
| Continuity | How often each is tested | Triggers first: new asset, new API, deploy, disclosed CVE. Then a schedule by criticality: P1 monthly or on change, P2 quarterly, P3 as events demand |
Two lines from that slide are worth lifting out. The first is a measurement change: measure validated coverage and time to verdict, not asset counts. Most exposure programmes report the opposite, and asset counts are exactly the metric a discovery-priced tool is built to produce.
The second is the governance condition, and it is the answer to the obvious worry about pointing offensive AI at your own estate. Automate depth only with scope control, human approval before active exploitation, and a full audit trail.
The order he now argues for, and the one he used to
In the session he was candid that this reverses a position he held publicly. FireCompass coined the term CART, continuous automated red teaming, and regulators had begun naming it as a requirement.
A year back, I was very happy that many of the regulators mentioned that CART should be mandatory. We were very happy because we created this acronym CART. But I believe, because of AI today, the priority should be depth first, and after that, breadth and continuity.Bikash Barai
His reasoning is affordability rather than principle. Continuous token cost is high enough that continuous deep assessment does not work at today's prices, so a continuous shallow layer belongs on top of the base rather than in place of it.
What happens if the debt is not paid down
His closing warning was operational. If the depth debt is not worked off deliberately, it gets called in on someone else's schedule.
Bounty hunters start reporting vulnerabilities. A vendor finds something and sends it to your management. Or there is a compromise. In each case the priority shifts from continuity to depth anyway, just not on your terms.
He also pointed to two public signals. The volume of vulnerabilities reported through bug bounty platforms has shot up. And Microsoft's most recent Patch Tuesday was the largest it has ever shipped. Tenable counted 964 CVEs in the September 2026 release, a record, including two zero-days already under active exploitation. AI is helping attackers and defenders find vulnerabilities more easily at the same time.
Now, that's a very scary thing, and that's also a very promising thing. Depending on which side you are.Bikash Barai
What to watch next
Bikash expects security testing to follow cloud into consumption-based pricing, because that is the only way depth at scale becomes affordable. Until it does, the practical move is the reallocation above: commodity-price the breadth, spend the difference on proving your P1 assets, and let triggers rather than calendars decide when a test runs.
You cannot out-scan an attacker who can now afford to outthink you. Prove your assets before they do.Bikash Barai, closing the session
Questions from the session
What is depth debt?
Depth debt is Bikash Barai's term for exposures that have been discovered and scored but never proven. It accumulates when a security programme can afford to enumerate its attack surface but not to validate whether any given exposure is actually exploitable.
What is the depth gap?
The depth gap is the difference between what an organisation can afford to spend testing an asset and what an attacker can afford to spend breaking it. On the numbers in this session that is half a cent per asset per day against roughly $300 per attempt, a ratio of 60,000 to 1.
Does this mean ASM and CTEM tools are worthless?
No. ASM was built for asset discovery, and automated discovery genuinely solves breadth. Bikash's argument is that a cent per asset per day buys enumeration, fingerprinting, CVE matching and a score, and cannot buy validation. The recommendation is to pay commodity prices for coverage and move the saved budget into depth, not to stop covering the estate.
How often should assets be tested?
His model puts triggers before schedules. A new asset, a new API, a deploy or a disclosed CVE should fire a test immediately. Underneath that sits a cadence by business criticality: P1 monthly or on change, P2 quarterly, P3 as events demand.
What should an exposure programme measure?
Validated coverage and time to verdict, rather than asset counts. Asset counts are the metric a discovery-priced tool is built to produce, and they say nothing about whether any exposure was proven.
Is it safe to run AI agents offensively against your own estate?
His stated condition is to automate depth only with scope control, human approval before active exploitation, and a full audit trail.
Five sessions remain, every Thursday through 22 October
Twenty minutes each, live. One registration covers the series. Free
New to CISO Platform? Join the community free for frameworks, checklists and peer discussion.
Technology Partner: FireCompass. All sessions, speakers and content in this series are produced and delivered by FireCompass. CISO Platform is hosting the series for its community.
Every figure, quote and recommendation above is drawn from the session recording and the slides presented, available here. The single exception is the Patch Tuesday CVE count, which is linked to its source in the text. The HackerOne figures are FireCompass's own, sourced on their slide to their US press release.