F5's Sean Murphy: The Gap Between Vulnerability and Exploit Has

F5's Sean Murphy: The Gap Between Vulnerability and Exploit Has "Basically Disappeared"

BackerLeader 43 231 394
calendar_today agoschedule2 min read

Sean Murphy spent nearly a decade as an F5 customer, running security at BECU and, before that, Premera Blue Cross, both in Seattle, before joining F5 itself this year as Field CISO. That vantage point shapes how he talks about the shift AI has forced on vulnerability management. "The curve between vulnerability and exposure and exploit is really gone," Murphy said. Frontier models have made attack activity relentless and continuous rather than something defenders could reasonably expect to get ahead of between scheduled patch cycles. F5 has responded by moving even its most conservative customers, organizations running air-gapped or on-premises BIG-IP deployments that historically patched on a much slower cadence, to monthly releases.

Murphy's other consistent theme is that AI governance can't default entirely to the security team. If an AI agent is making a real business decision, a credit risk determination inside a bank, for instance, the security organization shouldn't be the only party accountable for that outcome. Someone on the business side needs to own it too, in his view, or AI governance stays a compliance exercise instead of an actual operational discipline. He's candid that F5 isn't immune to the sprawl this creates internally either: the company's own CEO has encouraged employees to build their own agents, the kind of grassroots adoption that makes shadow AI a management problem before it's ever a security one.

That's the framing behind F5's SurePath AI acquisition, announced alongside the company's broader AI Security Platform in June: discovering unsanctioned AI tools and agents at the network level, without requiring integration into the applications themselves. Murphy was candid that shadow AI discovery isn't the top priority for most security teams day to day; detection and response for active threats still comes first, and shadow AI usually only escalates in priority once there's evidence of actual data leakage or unusual network behavior tied to it. Employees adopting unsanctioned AI tools aren't typically acting maliciously in his experience, just taking the path of least resistance to get work done faster, which is exactly why Murphy thinks visibility alone won't fix it. What organizations need, he argues, is the same asset-management discipline they've long applied to other technology: know what agents exist, who owns each one, and when it's supposed to be shut down, rather than letting agents accumulate indefinitely with no expiration built in.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13

TypeScript Complexity Has Finally Reached the Point of Total Absurdity

Karol Modelskiverified - Apr 23

Defending Against AI Worms: Securing Multi-Agent Systems from Self-Replicating Prompts

alessandro_pignati - Apr 2

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Tom Smithverified - Aug 3

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14
chevron_left
15.9k Points668 Badges
202Posts
119Comments
81Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

3 comments
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!