Most cybersecurity breaches are not caused by zero-days that nobody saw coming. They are caused by known vulnerabilities that were picked up by a tool, logged in a backlog, and never fixed. One of the reasons for this is that security teams were too overwhelmed by noise to act on the right things at the right time. Tonic Security, founded by incident response veterans, is building a platform designed to change that.
David Warshavki, co-founder and Chief Product Officer of Tonic Security, sat down with Techzine TV to discuss how the company is approaching exposure management differently. Warshavski has a background spanning decades of incident response work defending Fortune 500 and Global 2000 companies against nation-state threat actors from Russia, China, North Korea, and Iran. This means that he brings a practitioner’s perspective to the problem of alert overload that plagues modern security operations.
What is the real bottleneck?
The cybersecurity industry has long competed on detection. Vendors claim to find the most critical vulnerabilities, the most alerts, the highest percentage of threats that others miss. The result inside organizations is a backlog of millions of findings. Security teams can never realistically work through that backlog. Medium to large enterprises face this daily. The vast majority of those findings, Warshavski argues, will have no real impact on the organization. Some are false positives. Many are duplicates. But without the right context, security teams cannot confidently deprioritize anything. This means that everything piles up.
CVE scores and CVSS ratings make the problem worse, not better. Organizations that optimize for CVE counts end up with enormous backlogs of items that may not even be relevant to their environment. The question that matters is not just whether a vulnerability is exploitable in theory. It is whether it is actually running in the organization’s runtime, whether the vulnerable function is in use, and most importantly, whether exploiting it would reach and damage any business-critical system. That last question is why Tonic Security was built.
Business operational context at scale
Tonic Security positions itself as an exposure management platform that combines an insight layer with an execution engine. The foundation is a data fabric that goes further than integrating IT and security tools. The platform ingests unstructured data from tools like Slack, Notion, Confluence, Microsoft Teams, ServiceNow, Salesforce, SAP, and SharePoint to extract business operational context that has historically existed only as tribal knowledge.
This context extraction involves entity extraction and coreference resolution across sources. A conversation that starts on Slack may have its resolution documented in a Confluence page or an email thread. Tonic’s platform correlates these cross-source signals to build a picture of what each asset actually does for the business, who owns it, and what happens if it goes down. IT service tickets are particularly valuable here: a history of thousands of tickets showing what users complained about when they lost access to a specific system reveals the operational criticality of that system in a way that no asset inventory spreadsheet can.
Difference between exploitability and business blast radius
Warshavki draws a clear distinction between three layers of threat analysis: whether a vulnerability is exploitable, whether it is actually reachable in the organization’s specific environment, and what the business blast radius would be if it were compromised. Many tools address the first question. Some address the second. Very few address the third. Of course, the point he makes is that Tonic focuses on that question.
A vulnerability that is exploitable but self-contained, that cannot be used for lateral movement or privilege escalation, and that does not touch any business-critical system, is fundamentally different from one that sits on the path to the organization’s most sensitive assets. Without understanding the business context, security teams cannot make that distinction at scale.
The Tonic Mobilization Coordinator: from insight to automated action
Tonic Security has an agentic workflow, the Tonic Mobilization Coordinator. This can orchestrate and in some cases fully automate the remediation of vulnerabilities in what the company calls low-risk scenarios. These are situations where Tonic has high confidence that the remediation action will not cause downtime or disrupt a critical business process.
According to Warshavki, one of the underappreciated blockers to timely remediation is that security teams are afraid to patch things because they do not know what else might break. The business context that Tonic curates from collaboration tools gives teams the confidence to act, he says. In lower-confidence scenarios, the platform integrates a human-in-the-loop workflow, surfacing the relevant asset owners and recommending a course of action while keeping a person in the decision chain.
Warshavki describes Tonic as a decision and execution engine rather than just another alert console. The context it builds also feeds external tools. Organizations building their own DIY agentic workflows for identity management, firewall management, or change management can connect to Tonic via API or MCP server to access that business context and make confident automated decisions. SIEM solutions can similarly consume Tonic’s context to enrich their alerts with business blast radius information.
Where does Tonic fit in the existing security stack?
Tonic can displace or replace legacy vulnerability management tools such as Tenable, Rapid7, and Qualys, as well as some newer exposure management platforms, Warshavki states. It is also designed to coexist with existing tools depending on the organization’s operating model. In all cases, it serves as the orchestration layer that mainly answers one question: of everything that needs to be done, what should I do first, and can you do it for me when the conditions are right?
Deployment is flexible. For organizations in heavily regulated industries that cannot allow any data to leave their environment, Tonic offers fully on-premises deployment using self-hosted models. The minimum footprint required to demonstrate value is small after which the platform can expand across the environment incrementally.
Addressing burnout in security operations
Beyond the technical and business outcomes, we also talk about the human cost of the status quo with Warshavki. Burnout is a well-documented problem in cybersecurity. It is driven by the relentless volume of alerts, the adversarial nature of the work, and the feeling that the list never gets shorter. According to Warshavki, Tonic’s customers report that the platform’s ability to legitimately deprioritize the vast majority of findings frees up time and attention that security practitioners can redirect to strategic work.
The time savings matter not as a productivity metric but as a security outcome. When teams have time to focus on the handful of findings that genuinely matter, they prevent the next breach. Several customers have sent unsolicited thank-you notes, Warshavki says. Employees save time and can spend more time on work they actually care about.
What’s next for Tonic Security?
Tonic Security came out of stealth in July 2025 to strong market reception. It’s next frontier is opening up its context engine to a broader ecosystem. The company is working with external vendors and teams to do that. The platform is being made more open to support this.
Also read: Tonic Security emerges from stealth mode to offer AI-driven exposure management