HackerOne CEO Kara Sprague on how AI is reshaping cybersecurity

HackerOne CEO Kara Sprague on how AI is reshaping cybersecurity



https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/hackerone-ceo-kara-sprague-on-how-ai-is-reshaping-cybersecurity?
Kara Sprague is the CEO of HackerOne. Martin Harrysson is a senior partner in McKinsey’s Bay Area office.



HackerOne CEO Kara Sprague discusses how AI is reshaping the cybersecurity landscape and why security teams must shift from finding vulnerabilities to reducing exposure.



As frontier AI models—the most advanced generation of AI systems—make cyberattacks faster and more sophisticated, organizations are increasingly turning to companies such as HackerOne to enhance their defenses. In a conversation with McKinsey Senior Partner Martin Harrysson, HackerOne CEO Kara Sprague explored how AI is changing the risk landscape and why the real challenge is no longer finding vulnerabilities but remediating them before attackers can act.

This interview has been edited for length and clarity.

Martin Harrysson: We are at a moment where AI is reshaping many parts of technology. How did you enter the technology field, and what is structurally different in cybersecurity today compared with before the rise of AI?

Kara Sprague: I started my career at McKinsey, advising clients across the tech stack, then moved into industry at F5, which focuses on application delivery and security. Now I’m CEO of HackerOne, working with some of the world’s biggest companies to find and fix security weaknesses before they can be exploited.

Today, we’re seeing three things happening at once. First, the attack surface is growing because more AI models and systems are being deployed across more enterprises, and AI code generation is accelerating the pace at which companies build and deploy software. Second, that attack surface is more vulnerable because security for AI deployments is still nascent, and AI-generated code still tends to be less secure than human-generated code. And third, attackers are getting more capable because they are quickly adopting and weaponizing frontier AI capabilities.

Defense is behind, and it will take time to catch up. Enterprise security operations will have to retool for speed. And that’s not just about adopting new technology. It’s about rethinking the operating model, talent, and governance. The find-to-fix workflow has to be reimagined with AI at the forefront.

Martin Harrysson: Should leaders see the current landscape as a step change in risk or an acceleration of existing trends?

Kara Sprague: I would call it an acceleration of trends that have been visible for some time. The time between vulnerability discovery and exploitation, for example, has been steadily decreasing from over two years in 2018 to less than a day today.

What feels new in recent weeks, following Anthropic’s early April announcement of Mythos, is the step change in cyber-specific capabilities. Models can now build effective exploits that chain multiple vulnerabilities together, meaning even unsophisticated attackers can identify and target critical issues.

Martin Harrysson: The compression in timelines and the emergence of new attack vectors is significant. How well are organizations keeping up?

Kara Sprague: At HackerOne, we have a broad view across the market because we work with close to 20 percent of the Fortune 500 and almost 40 percent of the Fortune 50. What we’re seeing across our platform is that vulnerability reports have increased by 76 percent year on year. You might assume those reports are just more noise—what some refer to as “AI slop.” We have seen that in the past, but that’s not what we’re seeing now. The signal—the share of reports that turn into valid findings—has held steady, which means the increase is reflected in real vulnerabilities as well.

Defenders are struggling to keep up with threats. Backlogs are growing. The gap between new threats and the ability to respond is still measured in months, and sometimes years.

It really depends on how quickly security organizations are able to retool their operations for speed. There are emerging blueprints for what that looks like—for example, the Cloud Security Alliance’s recent work on building Mythos-ready security operations—but closing that gap will require significant changes to how organizations operate.

Martin Harrysson: In practical terms, what steps can organizations take to bridge the defense gap you’re outlining?

Kara Sprague: To meet this surge in AI-led vulnerability discovery, we need to meaningfully accelerate validation and remediation at scale.

At HackerOne, we’re investing in helping organizations overcome a few bottlenecks. First, agentic testing capabilities that incorporate the latest frontier models can find the same vulnerabilities that adversaries using models such as Claude Opus and Mythos would find—but agentic testing does it sooner. Second, agentic validation capabilities will be needed to absorb the coming surge in vulnerability volume while maintaining high signal rates. And third is remediation support—helping organizations move from finding the problem to implementing a verified fix faster and at scale.

Human expertise is critical for implementing these capabilities successfully. At HackerOne, nearly 90 percent of our global community of security researchers uses frontier models to find novel and elusive issues, and they test fixes to ensure they fully remediate exposure.

Martin Harrysson: To your point on the researcher community, how do you see the role of human researchers evolving as AI becomes more capable?

Kara Sprague: Human researchers are shifting from manual bug hunting to higher-level, more strategic work. AI is taking over the discovery of common, high-volume vulnerabilities, while researchers are increasingly focused on building tools and systems that use AI to find deeper, more complex issues such as logic flaws, architectural weaknesses, and novel attack paths.

You can compare autonomous code fixes to self-driving cars: For critical systems, the tolerance for error is essentially zero. Although AI can reliably propose fixes in greenfield projects, it cannot safely untangle complex, legacy architectural issues. Fixing these systems requires expert human oversight.

Ultimately, this evolution will lead to the market placing a much higher premium on identifying complex, high-impact vulnerabilities and guiding critical fixes while decreasing the payouts for lower-complexity issues handled autonomously by AI.

Martin Harrysson: Where do organizations tend to break down as vulnerability discovery accelerates? What does it take to prioritize and act effectively?

Kara Sprague: Organizations tend to break down at the handoff points. The typical workflow—finding an issue, filing a ticket, triaging, prioritizing, and patching—involves multiple handoffs, which create backlogs of work waiting to be processed. Those backlogs don’t hold up under volume. The organizations that perform well are the ones that shorten or minimize those handoffs and ensure findings arrive with enough context.

This is tricky. As the pace of discovery and exploitation accelerates, traditional boundaries between AppSec, DevOps, and SecOps5 become harder to sustain. Separating these functions also creates additional handoffs across teams, slowing response times. Instead, organizations may move toward more integrated workflows with shared data and priorities. Over time, this could mean shifting security from a separate function that inspects software after it is built to something embedded directly into how software is developed and run.

Martin Harrysson: Given those challenges around data, tooling, and organizational alignment, what will separate the organizations that get this right from those that don’t?

Kara Sprague: The biggest difference will be how quickly organizations can clear their backlogs and the extent to which they can compress their find-to-fix workflows. Many are still operating as if they have time between when a vulnerability is discovered and when it is exploited—but with AI, that time is gone.

Organizations that get this right treat it as a time-based problem. Those who fall behind are still managing volume—generating more findings than they can act on. This is where prioritization is important. Traditional vulnerability scoring systems provide a standardized view of severity, but they do not reflect actual risk in a specific environment. The same vulnerability can have very different implications depending on whether an asset is internet-facing, what data it processes, and what controls are in place around it.

Effective prioritization depends on context—combining an understanding of the asset, how a vulnerability can be exploited, and the organization’s capacity to remediate. Without that, even well-identified vulnerabilities can be prioritized incorrectly.

In the end, the advantage won’t go to the organization that finds the most vulnerabilities, but to the one that can reduce its risk exposure the fastest.


AI is already reshaping hospitality. This Deloitte digital exec assesses just how far it goes.


https://hotelsmag.com/news/ai-is-already-reshaping-hospitality-this-deloitte-digital-exec-assesses-just-how-far-it-goes/



More consequential than the Industrial Revolution. It’s how many are framing artificial intelligence: just as artificial intelligence. When ChatGPT is posed the question—” Why is artificial intelligence more consequential than the industrial revolution?”—it gives itself a pat on the back. “AI doesn’t just automate physical labor—it has the potential to automate and augment cognitive labor, which affects virtually every sector of the economy,” it responded instantly, then went on to drill down and get more granular on its impact—or is it upheaval?

Let’s ask. Another question for the LLM: “What is the upheaval from artificial intelligence on hospitality?” The answer was more of a salve than an irritant. “AI’s impact on hospitality is likely to be significant, but it will look different from its impact on [other] industries because hospitality is fundamentally a people business.”

It’s a more moderate take, to be sure—and that’s coming from the very thing that is responsible for the disturbance!

HOTELS Magazine wanted to hear from a human, so we turned to Oliver Page, principal and digital lead for transportation, hospitality and services at Deloitte Digital, for his takes on the sweeping changes to come operationally, how AI will improve the service of hospitality, and why the reports about the death of humans at the hands of AI are greatly exaggerated.

HOTELS: How do you envision AI reshaping the hospitality industry as it relates to the travel-booking experience, on-premises guest-facing operations, and back-of-the-house operations?

Page: AI will support the hospitality industry in three key areas: how guests discover and book their stays, how guests are serviced on property, and how hotels operate behind the scenes. In the booking experience, the shift is moving from guests actively searching for options to guests asking an AI agent to solve for their specific intent, budget, loyalty status, location and travel purpose. This transformation is already underway, with major brands collaborating with hotels and airlines to enable direct bookings through AI-powered responses.

Once on property, AI will help function as an intelligent service layer, supporting check-in processes, concierge services, guest requests, loyalty program interactions and service recovery efforts.

Behind the scenes, AI can optimize critical operations including labor allocation, housekeeping schedules, maintenance workflows, procurement decisions and revenue-management strategies.

HOTELS: What are the largest considerations for hotel executives now in employing and deploying AI? How should they prepare organizations?

Page: The biggest consideration for hotel leaders is determining organizational readiness versus embracing experimentation. Human approval and oversight will always be required, as leaders should carefully assess which workflows are safe for AI to assist with or fully automate.

Data fragmentation will present a significant challenge, as many organizations will discover that legacy systems are not connected. To address this, organizations will need to prioritize building a strong data foundation, resolving identity conflicts and establishing proper data access protocols.

The most successful implementation path will be to start with tightly focused workflows, build trust through proven results and appropriate controls, and then scale both the scope of AI applications and the level of autonomy granted to these systems.

HOTELS: Where is the biggest opportunity for AI related to generating more revenue? Conversely, how can AI help reduce costs?

Page: AI can strengthen direct booking, pricing, loyalty, upsell and ancillary revenue by making everything more relevant—delivering the right offer at the right time and the right place. On the cost side, AI can reduce expenses by removing friction from repetitive work.

All forms of intent recognition, routing and dispatch, including messaging, housekeeping coordination, maintenance scheduling, waste management, and forecasting, represent areas for potential ways for organizations to reduce costs. However, these gains will need to be managed alongside model costs. Small language models (SLMs) are finding particular value in this space, as they lower the cost of serving while also improving consistency in some cases compared to frontier models.

HOTELS: How do you foresee AI impacting the workforce? Will it remove jobs and/or make employees more productive?

Page: The workforce will remain critical to the future of hospitality as job titles evolve and productivity improves. The best hotel companies will deploy AI to amplify their teams, allowing their employees to spend less time on routine tasks and more time delivering exceptional hospitality.

HOTELS: Does the velocity of AI worry you? What types of drawbacks are there?

Page: The winners will not simply be companies that deploy more AI, but rather those that combine a human-in-the-loop with trusted identity, robust governance, right-sized intelligence and controlled autonomy.


What matters most to investors in 2026 and what it means for companies



https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/what-matters-most-to-investors-in-2026-and-what-it-means-for-companies?
Ezra Greenberg is a partner in McKinsey’s Connecticut office, Jennifer Heller is a partner in the Bay Area office, Ryan Davies is a senior partner in the Washington, DC, office, Sébastien Lacroix is a senior partner in the Paris office, and John Evers is a knowledge expert in the Toronto office.



Even before the Middle East conflict began, geopolitics surged as the foremost investor concern. AI disruption and capital allocation discipline are also top of mind.



Surveys of investor sentiment tend to reveal a similar list of issues from year to year. But how investors rank those concerns can change dramatically, signaling where companies need to focus their messaging. McKinsey’s latest investor survey (see sidebar, “Our methodology”) reveals that geopolitics surged ahead of other preoccupations even before the conflict in Iran began at the end of February. The survey reveals two other themes—AI disruption and capital allocation discipline—to which investors are paying maximum attention.

Each of these themes is important for companies to bear in mind as they communicate with investors. But our experience suggests they are best addressed in tandem. Companies that can demonstrate resilience, connect AI to operating economics, and show disciplined capital allocation are more likely to earn long-duration investor commitment.

Geopolitics has become a top concern for investors


Sixty-nine percent of respondents place geopolitics among the top three macro themes influencing their investment decisions this year (Exhibit 1). This finding echoes the results of McKinsey’s previous CFO survey, where geopolitics was also top of mind for finance team leaders. Over a third of investor respondents rank it as their very top concern, nearly double the rate of any other single theme, and also rank it as the most underpriced risk in markets and their top concern for the investment climate.


Exhibit 1
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



Three themes are roughly tied for the second-most-cited topics that are influencing investment decisions this year: technology and productivity, inflation, and interest rates. By contrast, in the next-most-recent survey, conducted in late 2024, investors ranked geopolitics, inflation, and interest rates as of roughly equal importance.

Investors are intensely concerned about geopolitical risks

Respondents not only rank geopolitics at the top of their lists of preoccupations but also express high degrees of worry about it (Exhibit 2). Sixty-nine percent of investors report high levels of concern about geopolitical instability (giving it a 4 or 5 rating on a five-point scale), including 18 percent who select “extremely concerned.” Notably, no respondents selected “not concerned.”


Exhibit 2
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content, we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



Within geopolitics, respondents appear most focused on great-power systemic risks, as opposed to regional instability. When asked to choose their three most pressing geopolitical concerns, 74 percent of respondents chose “trade restrictions and tariffs,” 67 percent “major power conflicts,” and about half “sanctions or fragmentation of global systems.” About a quarter include emerging-market political instability, and just under a quarter choose energy security.

Investors believe geopolitical risk is underpriced

A question asking respondents to choose up to ten underpriced risks reveals perhaps the most consequential finding of this survey: Respondents most frequently choose (at 32 mentions) geopolitical conflict as the most underpriced risk, well ahead of persistent inflation (20 mentions), tariff uncertainty (18), financial liquidity (10), climate transition (9), and AI disruption (9) (Exhibit 3).


Exhibit 3
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content, we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



When investors say a risk is “underpriced,” they mean markets are too complacent and that the probability or magnitude of a negative outcome is higher than current valuations reflect. This perception matters because it indicates where investors look for differentiation: If they believe geopolitical risk is underpriced, they are likely to actively probe whether a company’s management team has quantified its exposure or is simply hoping the risk doesn’t materialize.

Perceptions of mispricing have practical implications for corporate leaders. Investors who believe a risk is underpriced are acutely sensitive to companies’ exposure. They are likely to feel more positively about management teams that articulate their approaches to tariff pass-through mechanics, supply-chain resilience, and geographic-revenue concentration.

Investors now consider AI adoption crucial—but want to see results

In this survey, respondents resoundingly express how important it is for a company to have a clear and dynamic approach to AI adoption. That’s a big change from just four years ago, when AI didn’t even come up as a topic in our 2022 investor survey, and from two years ago, when it was a rising but not yet central theme.

But another notable shift since the previous survey is the emergence of AI-related anxiety. “AI bubble risk” and “market concentration” now rank fourth and fifth among investment climate concerns.

Respondents think AI adoption and tech clarity make companies winners …

In open-ended descriptions of what makes a company a “winner” in 2026, respondents most frequently (34 times) mention something relating to AI, followed by topics relating to operational resilience (32), strong cash flow (28), and durable competitive advantage (22) (Exhibit 4). In our 2024 survey, only 31 percent of respondents even included AI and technology utilization as a characteristic of a winning company.


Exhibit 4
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content, we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



In the 2026 survey, 77 percent of respondents rate AI and a clear tech angle as highly important (7 or above on a 1 to 10 scale), and 31 percent rate it as a 9 or 10. Only 3 percent assign relatively low importance to AI adoption (Exhibit 5).


Exhibit 5
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com


… but when it comes to AI, respondents want to see results

A question about what investors view as the greatest risks to the investment climate reinforced that geopolitics, inflation, and interest rates are major concerns. But large numbers of responses also reflect worries about “AI bubble risk” and “market concentration” (Exhibit 6).


Exhibit 6
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



We surmise that investors make a distinction between companies that connect AI investments to measurable operating outcomes—margin improvement, productivity gains, customer acquisition economics, or defensible technical advantage—and those that aren’t clear about the profit-and-loss impact of their AI investments. Given rising concerns that AI enthusiasm may have outpaced reality, it’s unsurprising that investors are demanding tight capital discipline and a clear path to ROI.

Capital allocation discipline: The constant across every survey

A majority of respondents considers disciplined capital allocation to be a core condition of their long-term investment theses (Exhibit 7).


Exhibit 7
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



It’s important to note that organic reinvestment is the preferred use of capital (52 percent of respondents rank it first) (Exhibit 8).


Exhibit 8
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content, we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



For 63 percent of respondents, ROIC discipline is the hallmark of a quality capital allocator, while 54 percent look for a clear allocation framework (Exhibit 9). These responses echo our survey from 2022, when capital productivity ranked among the top three drivers of long-term value creation, and our 2024 survey, when half of respondents said they prioritize EBITDA to evaluate company performance and a third said they prioritize ROIC.


Exhibit 9
We strive to provide individuals with disabilities equal access to our website. If you would like information about this content, we will be happy to work with you. Please email us at: McKinsey_Website_Accessibility@mckinsey.com



In short, even as the macro backdrop changes, some investor expectations do not: Intrinsic investors want to see disciplined capital allocation governed by return on capital.

Implication for companies


In our experience, investors assess three elements to gauge how attractive a company is as an investment:
  • Resilience: How able is the company to make strategic bets amid uncertainty?
  • AI credibility: Is the company’s AI story grounded in operating economics? Can it connect investments to margins, productivity, and/or defensible advantage?
  • Cash and capital discipline: Does the company generate cash and allocate it rigorously, even amid uncertainty?

These considerations work best in unison. A strong AI story without geopolitical resilience could leave investors worried about concentration risk. Cash discipline without a credible growth narrative makes investors wonder where compounding will come from. Our read of the data is that companies best positioned to attract long-duration capital are those that can address all three filters in a coherent, integrated way.

In light of investors’ current concerns and priorities, we propose the following recommendations for companies:
  • Respond to geopolitical risks tactically and strategically. Many companies have done a good job offering investors a clear-eyed view of exposure and resilience in the face of uncertainty. The best communicators explain what percentage of revenue is exposed to tariff-affected corridors, what the pass-through mechanics look like, and what contingency plans exist if a second-order disruption (such as sanctions escalation or supply chain rerouting) materializes. However, this kind of tactical resilience is now table stakes, while strategic resilience can set management teams apart. Those able to make strategic bets, even under conditions of uncertainty, are more likely to capture investor attention.
  • Connect AI investment to operating economics. AI has swiftly moved from an emerging theme to the most-cited “winner” characteristic, but investors are also concerned about overshooting the target. Companies should be prepared to explain how their AI investments translate into financial results, whether through margin expansion, productivity improvement, customer acquisition economics, or a defensible technical moat.
  • Emphasize capital allocation and cash discipline in the company’s equity story. Investors will be interested not just in whether companies have a capital allocation framework, but whether it holds under stress. The strongest signal a management team can send is that AI investment, M&A, and organic reinvestment are all governed by the same ROIC discipline, and that the framework has been pressure-tested against the scenarios of greatest concern to investors.

Taken together, these recommendations speak to what investors are really looking for: not a strategy that changes with every headline, but one that was stress-tested against a range of macro scenarios. Strategies need to be flexible enough to absorb geopolitical shocks, disciplined enough to hold the line on capital allocation, and—if relevant—grounded enough in AI that the investment thesis holds even if the market reprices. Rapid tactical responses to unexpected risks are now table stakes. The leaders who can create a robust strategy in the face of uncertainty and stick to it are likely to lead their companies to outperformance.





DUHC&S | Strategic Hospitality Consulting & Advisory

We transform hospitality and tourism businesses through strategic solutions, operational efficiency, and comprehensive renovation. With over 40 years of experience working with brands like Hilton, Hyatt, Sheraton, and Sonesta, we enhance asset value and profitability through:

*Operational excellence and brand standards (GSI +90%)
*Market penetration and commercial strategies
*Key partnerships and disruptive innovation
*Hotel openings and repositioning


Proven results :
✅ 48% GOP |
✅ +120% asset valuation growth
✅ Successful projects across 6 Latin American countries


🔹 Let's connect :
📱 WhatsApp: +57 3153259968
    Instagram: https://www.instagram.com/diur_2000/


              https://viajes-noticias-duhospitality.blogspot.com
              https://viajes-duhospitality.blogspot.com
              https://travel-duhospitality.blogspot.com



Disclaimer

DUHC&S shares this information for educational and informational purposes only. The news articles reproduced here are sourced from public and recognized media outlets. We are not the original authors of this content but rather its distributors. All credits go to the original sources cited in each article. If you are the legitimate owner of any material and wish to have it modified or removed, please contact us immediately at diurugeles@gmail.com, and we will address your request promptly.


Comments

https://travel-news-duhospitality.blogspot.com