The Dallas-Fort Worth Chapter of ISC2 is based in the DFW area and serves the counties of the Dallas-Fort Worth Metroplex and North Texas Region. Members include those with security certifications from ISC2 as well as other professionals practicing or interested in information, software, and communications security, and the PUBLIC. Our mission is to advance information security in the DFW area by providing our members and other security professionals with the opportunity to share knowledge, grow professionally, educate others, and collaborate on projects. Our chapter programs provide members a forum to facilitate the exchange of knowledge and ideas, the development of leadership and professional skills, and the advancement of information systems security. We also provide our members with access to a variety of industry resources and educational programs to keep them up to date with the latest advances in technology as well as information assurance.

Exploitability Over Vulnerability: Lessons from Autonomous Pentesting

Tony Taylor – Horizon3 Talk – 8/28 NOON -1 pm

(With a few minutes delay for and you can join in as soon you are available)

Tony Taylor has spent more than 30 years at the intersection of infrastructure, cybersecurity, and business strategy. His career has taken him from building and operating enterprise technology environments to leading global teams, advising organizations on cyber strategy, and helping security leaders navigate an increasingly complex threat landscape. Today, as a Senior Sales Engineer at Horizon3.ai, he works with organizations to better understand cyber risk through an attacker’s perspective, bringing a practical, experience-driven approach that connects technical realities with business priorities.

The cybersecurity industry has become exceptionally good at finding vulnerabilities, yet many organizations still struggle to answer the question that matters most: What can actually be exploited? As vulnerability disclosures continue to grow and AI accelerates both attack and defense, security teams are overwhelmed with findings while executives are left searching for meaningful measures of risk.

After years of observing autonomous pentesting across organizations of every size, one lesson stands above the rest: attackers do not think in vulnerabilities. They think in opportunities. They exploit identity, trust relationships, weak segmentation, misconfigurations, exposed credentials, and the unintended connections between systems. More often than not, the greatest business risk is not a single critical CVE, but a chain of individually “acceptable” weaknesses that together create a path to compromise.

This session shares practical lessons learned from autonomous pentesting engagements and explores why organizations should shift their focus from vulnerability counts to exploitability. Rather than discussing products or point solutions, we’ll examine how continuous offensive validation changes the conversation around prioritization, remediation, and executive reporting. We’ll discuss why proving a control works is more valuable than assuming it does, why measuring attack paths provides greater insight than measuring findings, and why security outcomes—not security activity—should define success.

Attendees will leave with a framework for evaluating cyber risk through the lens of exploitability, practical guidance for prioritizing remediation based on demonstrated impact, and a new perspective on how offensive security can help organizations reduce noise, improve resilience, and build confidence that their defenses will stand up to real-world attacks.

This form is currently closed for submissions.

About Us

Our chapter provides members a forum to facilitate the exchange of knowledge and ideas, development of leadership and professional skills, and advancement of information systems security. We also provide our members with access to a variety of industry resource and educational programs to keep our members informed of the latest advances in technology and techniques.