Techzine TV podcast
In the Techzine TV podcast we analyze B2B IT solutions, strategies, and trends. IT companies are happy to invite us to talk about what they are working on and what they are going to bring to market. We visit them all around the world, and in some cases, they visit us in our office.
We have a good understanding of how technologies work, or how they should work. We also hear a lot from the market about what companies need or where things go wrong. This gives us the ability to have really in-depth conversations on technology, strategies, and products, but we always try to keep it practical and easy to understand.
We explain innovations, interpret new IT concepts, and use practical examples to make complex technology understandable for everyone. Where necessary, we bring in experts to clarify matters further. The goal is to help IT professionals, decision makers, and other listeners better understand IT developments, but also to help them in their search for new solutions for their business and not get stuck on buzzwords and one-liners.
The Techzine TV podcast is an evolution of the previous Techzine Talks on Tour series. We still bring a lot of conversations and interviews from events to this series. We record so many video interviews nowadays, so we can select the best ones for this podcast series.
The topics still vary greatly, as Coen and Sander attend a total of 50 to 60 events each year, ranging from open-source events like KubeCon to events hosted by Cisco, IBM, Salesforce and ServiceNow, to name only a few. With a lot of experience in many walks of IT life, Coen and Sander always manage to produce an engaging, in-depth discussion on general trends, but also on technology itself.
So follow the Techzine TV podcast and stay in the know. We might just tell you a thing or two you didn't know yet, but which might be very important for your next project or for your organization in general. Stay tuned and follow Techzine TV.
Techzine TV podcast
Tonic Security wants to fight alert fatigue with context
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
David Warshavski, co-founder and Chief Product Officer of Tonic Security, joins Techzine TV to talk about how his company is rethinking exposure management from the ground up. He can draw on decades of incident response experience defending Fortune 500 companies against nation-state threat actors from Russia, China, North Korea, and Iran, and has seen that cybersecurity isn't about finding vulnerabilities, but about prioritizing and fixing the right ones before a breach occurs. This sounds like common sense, but is actually quite rare in the cybersecurity industry.
Tonic Security wants to address the problem of alert overload by building a context engine that taps into both IT/security tools and collaboration platforms like Slack, Notion, Confluence, Teams, and ServiceNow. By extracting business operational context from unstructured data, Tonic can determine whether a vulnerability is exploitable. Not only that, it can also determin whether exploiting it would actually impact critical business processes. That last distinction should fundamentally change how security teams spend their time.
The platform acts as both an insight layer and an execution engine. It features the Tonic Mobilization Coordinator. This is an agentic workflow that can fully automate remediation in low-risk scenarios, Warshavski tells us. We also discuss how Tonic can replace legacy vulnerability scanners like Tenable, Rapid7, and Qualys, how it feeds context to DIY agentic workflows and SIEM solutions, and why opening up to an ecosystem is the company's next frontier.
Key takeaways:
• Most security breaches involve vulnerabilities that were already known but not properly prioritized or remediated in time
• CVE and CVSS scores alone do not reflect real business impact and create massive, misleading backlogs
• Tonic Security ingests unstructured data from collaboration tools to determine true business criticality of assets
• The platform differentiates between exploitability, reachability, and actual business blast radius
• The Tonic Mobilization Coordinator automates remediation in high-confidence, low-risk scenarios
• Security teams report significant time savings, reduced burnout, and freedom to focus on strategic priorities
• Tonic can displace legacy scanners and act as a context engine for other security tools via API and MCP server
• Fully on-premises deployment is available for heavily regulated industries
Chapters:
0:54 - David Warshavski's background in incident response
2:15 - Why Tonic Security was founded
5:32 - The prioritization problem and CVE noise
9:03 - Understanding business impact and context
17:17 - Tonic as a decision and execution engine
20:53 - Reducing alert fatigue and saving security teams time
27:44 - Where Tonic fits in your security stack
33:12 - Flexible deployment and next frontiers