Techzine TV podcast

Tonic Security wants to fight alert fatigue with context

Coen or Sander Season 3 Episode 14

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 36:54

David Warshavski, co-founder and Chief Product Officer of Tonic Security, joins Techzine TV to talk about how his company is rethinking exposure management from the ground up. He can draw on decades of incident response experience defending Fortune 500 companies against nation-state threat actors from Russia, China, North Korea, and Iran, and has seen that cybersecurity isn't about finding vulnerabilities, but about prioritizing and fixing the right ones before a breach occurs. This sounds like common sense, but is actually quite rare in the cybersecurity industry.

Tonic Security wants to address the problem of alert overload by building a context engine that taps into both IT/security tools and collaboration platforms like Slack, Notion, Confluence, Teams, and ServiceNow. By extracting business operational context from unstructured data, Tonic can determine whether a vulnerability is exploitable. Not only that, it can also determin whether exploiting it would actually impact critical business processes. That last distinction should fundamentally change how security teams spend their time.

The platform acts as both an insight layer and an execution engine. It features the Tonic Mobilization Coordinator. This is an agentic workflow that can fully automate remediation in low-risk scenarios, Warshavski tells us. We also discuss how Tonic can replace legacy vulnerability scanners like Tenable, Rapid7, and Qualys, how it feeds context to DIY agentic workflows and SIEM solutions, and why opening up to an ecosystem is the company's next frontier.

Key takeaways:
• Most security breaches involve vulnerabilities that were already known but not properly prioritized or remediated in time
• CVE and CVSS scores alone do not reflect real business impact and create massive, misleading backlogs
• Tonic Security ingests unstructured data from collaboration tools to determine true business criticality of assets
• The platform differentiates between exploitability, reachability, and actual business blast radius
• The Tonic Mobilization Coordinator automates remediation in high-confidence, low-risk scenarios
• Security teams report significant time savings, reduced burnout, and freedom to focus on strategic priorities
• Tonic can displace legacy scanners and act as a context engine for other security tools via API and MCP server
• Fully on-premises deployment is available for heavily regulated industries

Chapters:
0:54 - David Warshavski's background in incident response
2:15 - Why Tonic Security was founded
5:32 - The prioritization problem and CVE noise
9:03 - Understanding business impact and context
17:17 - Tonic as a decision and execution engine
20:53 - Reducing alert fatigue and saving security teams time
27:44 - Where Tonic fits in your security stack
33:12 - Flexible deployment and next frontiers