There’s a phrase that keeps surfacing in cybersecurity conversations lately: you cannot protect what you can’t see. It sounds simple. But for most organizations — from Fortune 500s to federal agencies — achieving that full-spectrum visibility is anything but.
That’s the challenge Tenable has built its entire company around solving. As “the exposure management company,” Tenable helps organizations move beyond the exhausting exercise of cataloguing vulnerabilities toward something far more strategic: understanding which exposures are most likely to cause real business disruption, and acting on those first.
We sat down with Jill Shapiro, Tenable’s VP of Global Government Affairs, on the World Lens Podcast to get her take on the evolving threat landscape, Maryland’s standing as a cyber powerhouse, and why AI might be the industry’s most double-edged sword.
From Noise to Decision Clarity
For years, cybersecurity tools did exactly one thing: find vulnerabilities and add them to an ever-growing list. The result? Security teams drowning in alerts with no way to distinguish the critical from the cosmetic.
Tenable’s approach is fundamentally different. “We help leaders focus on the issues most likely to lead to real business disruption rather than just trying to fix everything at once,” Shapiro explained. By providing visibility across the entire modern attack surface — traditional IT, cloud environments, operational technology, IoT, identity systems, web apps, and even AI infrastructure — Tenable gives organizations a unified risk picture that actually enables decision-making.
The key insight: no organization can fix everything. Trying to do so spreads teams thin and, paradoxically, leaves organizations more exposed. Effective prioritization brings together threat likelihood, asset criticality, and business impact to direct remediation efforts where they actually move the needle.
AI: The Threat That Defends Itself (and Attacks You)
Perhaps no topic generated more nuance in our conversation than artificial intelligence. AI is simultaneously the most powerful tool available to cybersecurity defenders and an accelerant for the attackers trying to breach them.
“AI is compressing time and scale for attackers, not just defenders, making the speed of understanding risk more important than ever,” Shapiro noted. Tenable’s platform, Tenable One, uses AI to continuously discover AI-connected assets across internal and external systems, mapping how AI infrastructure connects to broader networks, identities, and data. The goal is a risk-aware view that helps security teams focus on what matters most.
On the responsible use side, Tenable emphasizes transparency and governance in how AI is developed and deployed within its own products, ensuring the technology reduces risk rather than quietly introducing new attack surfaces.
Mission-Driven by Geography: Why Maryland Leads in Cyber
Tenable’s Columbia, Maryland headquarters isn’t incidental; it’s a strategic asset. The state’s cyber ecosystem is uniquely shaped by its proximity to the NSA and federal agencies, and by a culture where cybersecurity isn’t theoretical. “Cybersecurity here is tied directly to national security, resilience, and public trust,” Shapiro said.
She also highlighted the leadership of Governor Wes Moore and Secretary of Commerce Harry Coker in treating cyber as both a core security mission and a catalyst for economic growth, ensuring that policy, talent development, and private-sector needs evolve together.
What Government Should (and Shouldn’t) Do
Shapiro was clear-eyed about the federal government’s role: provide clear, risk-based guidance aligned with recognized frameworks like NIST, and sustain the public-private collaboration infrastructure that actually works — CISA’s Joint Cyber Defense Collaborative, the IT Sector Coordinating Council, and NIST’s National Cybersecurity Center of Excellence among them. The goal isn’t more regulation for its own sake; it’s alignment between regulators, industry, and operators around shared risk and faster recovery.
The Question Nobody’s Asking
We ended the conversation with a challenge: what’s the one cybersecurity question organizations should be asking but almost never do?
Shapiro’s answer: “Do you have a unified, real-time map of your entire attack surface that allows you to identify and remediate exposures most likely to disrupt critical business functions?”
Most organizations don’t. And that gap — between the complexity of the modern attack surface and the visibility organizations actually have — is precisely where the next major incident is waiting.
