# Beating “Checkbox Security” With Continuous Offense with Sonali Shah Page: https://stenobird.com/podcast/hacker-valley-studio-344898/beating-checkbox-security-with-continuous-offense-with-sonali-shah Text version: https://stenobird.com/podcast/hacker-valley-studio-344898/beating-checkbox-security-with-continuous-offense-with-sonali-shah.md Podcast: [Hacker Valley Studio](https://stenobird.com/podcast/hacker-valley-studio-344898) Published: 2026-02-12T14:00:00+00:00 Episode link: https://HackerValleyStudio.podbean.com/e/beating-checkbox-security-with-continuous-offense-with-sonali-shah/ Audio file: https://mcdn.podbean.com/mf/web/bwn59x36sax2z6u9/HVS26_EP414_Cobalt_Full_EP_mp37a5nh.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/hacker-valley-studio-344898/episodes/beating-checkbox-security-with-continuous-offense-with-sonali-shah Duration seconds: 2491 ## Resource Security doesn’t fail because you missed a tool, it fails because “secure today” tricks you into relaxing tomorrow. This episode exposes why the real fight isn’t compliance… it’s whether your defenses hold up once attackers hit you with machine-speed pressure. Ron sits down with Sonali Shah, CEO of Cobalt, to talk about how human-led, AI-powered penetration testing is evolving into full-spectrum offensive security. Sonali shares how Cobalt can start a test in 24 hours, push findings directly into Slack/Teams and Jira, and use learnings from 5,000+ pentests a year to continuously sharpen what gets caught. The big takeaway: automation finds the easy stuff as humans find the business-logic traps and attack chains that actually break companies. Impactful Moments00:00 - Introduction02:21- Sonali’s unexpected CEO path06:10 - Compliance isn’t real security10:19 - PTaaS: start in 24 hours12:33- 5,000 pentests yearly scale17:01 - Humans beat automation limits20:16 - AI behavior vulnerabilities emerge27:54 - Indirect prompt injection explained30:51 - Why juniors + AI is risky38:27 - 2026 becomes AI battleground LinksConnect with Sonali on LinkedIn: https://www.linkedin.com/in/sonalinshah/ Check out Cobalt: https://www.cobalt.io ____Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional:https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/ ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/hacker-valley-studio-344898/episodes/beating-checkbox-security-with-continuous-offense-with-sonali-shah/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/hacker-valley-studio-344898/beating-checkbox-security-with-continuous-offense-with-sonali-shah.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.