IT Tech Pulse Exclusive Interview with Chris Wallis founder and Chief Executive Officer of Intruder
Stay updated with us
Sign up for our newsletter
IT Tech Pulse speaks with Chris Wallis about exposure management, AI pentesting, and securing organizations against rapidly evolving threats.
You started your career as an ethical hacker breaking into major UK enterprise networks. What was the moment that made you say, ‘I need to stop hacking for others and build something of my own?
When Heartbleed dropped in 2014, I saw all these huge organizations with expensive security tools struggle with manual effort and alert fatigue. I couldn’t understand why security platforms weren’t automatically filtering the needles from the haystack, which made me realize software needed to do a better job. That frustration inspired me to build an automated solution that cuts through the noise to immediately prioritize actual, internet-facing risks.
You bootstrapped Intruder from a garden shed near GCHQ’s Cyber Accelerator on a shoestring budget. How did that lean, almost scrappy start actually shape the product and company culture you have today?
I was sleeping in a friend’s shed just to get by on my tiny GCHQ accelerator stipend, so we had to be careful with every single dollar. That forced us to pivot to a self-service credit card model, which basically baked ‘product-led growth’ into our DNA before we even knew the buzzword. Honestly, that scrappy foundation is the exact reason we are still so obsessed with the customer of today.
Read More: ITTech Pulse Exclusive Interview with Nicholas Janouskovec Global Cybersecurity Business Development Manager at Emerson
Vulnerability management has existed for decades. You’ve positioned Intruder around exposure management instead. What is the critical difference, and why has that distinction taken this long for the industry to accept?
Traditional vulnerability management has turned into a game of whack-a-mole. It dumps massive lists of potential flaws on your desk without any context on real-world urgency, leaving teams completely overwhelmed by data. Exposure management actually fixes this by shifting the focus to continuous detection, prioritisation and validation. The industry has honestly slow-walked these elements because everyone is still trapped relying on manual scheduling and over-engineered legacy tools.
Your 2026 ASM Index found 26% of organizations still leave MySQL databases exposed to the internet. Frankly, how does a known, well-documented risk like this remain unresolved at this scale across thousands of security teams?
These database exposures remain unresolved because lean IT and security teams are overwhelmed by the massive influx of unprioritized alerts from traditional scanners. Without continuous attack surface management to automatically flag hidden and internet-facing assets, these risks simply get lost in the noise.
The Index showed midmarket firms take up to 56 days to remediate exposures, nearly four times slower than smaller ones. Is the midmarket being structurally underserved by the security industry, or is this a self-inflicted problem?
The midmarket is absolutely underserved. We refer to the midmarket as a “Security Middle Child,” and our recent research revealed that 29% of midmarket organizations have outgrown simple SME tools, but 46% find that enterprise software assumes more staff and complexity than they possess. This fundamental mismatch leaves 42% of these security teams feeling stretched or behind, explaining why their remediation times drag out to 56 days as they struggle to navigate an over-engineered tech stack.
With the emergence of autonomous AI models capable of discovering zero-days at scale, the window between vulnerability discovery and exploitation is compressing fast. What does that mean for how organizations must rethink response time benchmarks entirely?
AI-driven exploit windows have collapsed from months to hours. Security professionals already exist in a fast-paced work environment, but AI has increased the speed even further. Organizations cannot rely on the traditional playbook of quarterly pentests, which leaves companies facing windows of compounding risk. Response benchmarks need to shift toward continuous exposure management and on-demand AI pentesting, replacing manual methods that take hours with autonomous agents that secure perimeters in minutes.
Read More: ITTech Pulse Exclusive Interview with Dean Valentine, CEO and Co-founder of ZeroPath
Your data shows banks remediate exposures in 11 days while insurance and pharma take over 40. Beyond compliance pressure, what structural or cultural factors explain why sectors with equally sensitive data perform so differently on basic hygiene?
The difference between sectors really comes down to an operational maturity gap. Having worked within global banks, I know these institutions have historically integrated both offensive hacking and defensive operations to manage their environments, structurally streamlining their attack surface reduction into agile, day-to-day processes that allow them to remediate flaws within 11 days. Meanwhile, the insurance and pharmaceutical sectors are bogged down by legacy complexity that slows execution and don’t have the same regulatory pressures as banks, dragging remediation out to 40–50 days and leaving critical windows wide open for basic, non-CVE exposures like exposed databases or admin panels.
For security leaders heading into the second half of 2026, facing AI-accelerated threats and growing attack surfaces, what is the one foundational shift in mindset or practice they absolutely cannot afford to delay any further?
Security leaders need to shift their mindset from simply patching what’s vulnerable to questioning whether an asset should be exposed to the internet at all. Moving into the second half of 2026, teams cannot afford to delay proactive attack surface reduction. They must remove what’s exposed before it becomes a problem rather than chasing endless, unprioritized vulnerability lists. AI pentesting is a great tool for this, as it brings an automated depth of analysis to your attack surface. Time to exploit has gone from months to hours, so security professionals need to shift away from annual or quarterly pentests, which have long been unfit for purpose, to protect their organisations.
Thank you, Chris, for taking the time to share your insights with us.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.
Chris Wallis is the founder and CEO of Intruder. With deep experience in both offensive security and defensive operations, Chris has worked hands-on with global banks, major financial institutions, and critical national infrastructure, securing some of the most targeted and high-risk environments in the world. This blend of attacker-led insight and real-world defense crafted Intruder’s practical approach to finding and fixing the vulnerabilities that matter, before they can be exploited.
Intruder’s exposure management platform helps lean security teams stop breaches before they start by proactively discovering attack surface weaknesses. By unifying AI penetration testing, attack surface management, cloud security and continuous vulnerability management in one intuitive platform, Intruder makes it easy to stay secure by cutting through the noise and complexity. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Learn more at https://intruder.io.