AI Software
September 25, 2026

How a Solo CISO Validated an Attack Surface in Days to Secure a New Customer

Metrics
85%-95%
Faster turnaround time
17 mins
To surface first findings
99%
Reduction in findings noise
Table of contents

Schedule a Demo

Highlights

Gaining ease and efficiency
RunSybil enabled a one-person security team to evaluate the company’s attack surface in days instead of potentially months.
Securing a key business win
The startup satisfied a prospective customer’s security requirements on a tight deadline, clearing the way to close a key deal.
Building trust to scale a small business
For a security-focused small business, growth depends on trust, and that means being able to verify their security posture to scale safely.

‍

RunSybil enabled a startup to simultaneously generate critical audit evidence, build out its new security program, and close a deal for a key customer win. And they did all of it while slashing total turnaround time by 85% to 95%.

“I had an urgent need for an external pentest for a potential customer deal we were trying to close,” says Joseph Moles, CTO and CISO at Furl.ai, a California-based cybersecurity company. “I had to have that evidence for their security check. Normally that kind of turnaround would have taken weeks or months, but I didn’t have that kind of time for this. Luckily, I had the first findings in 17 minutes. If relief could be measured in a metric, it would have been big.

“In terms of a fast turnaround, ease of use, and a low overhead, RunSybil gave me what I needed so we could meet those requirements,” he adds. “It helped us get that customer.”

Furl is a seed-stage cybersecurity startup with eight customers and fewer than 20 employees. The company acts as an autonomous remediation layer, using its always-on AI agent to generate, test, and deploy fix scripts for software vulnerabilities, without requiring manual patching from customer teams.

To continue growing the company, Moles, an experienced executive who served as CTO for 12 years at cybersecurity company Red Canary, was called on to validate the security of Furl’s attack surface.

He needed to deliver mandated results on a short timeline. If they didn’t get the validation in time, they’d lose out on a customer. And for a small business just getting started, getting this business to sign up was a big win.

The Challenge: Multiple Needs on a Tight Timeline

Moles wears multiple hats, acting not only as CTO but as the company’s one-person IT department and its sole cybersecurity-focused employee. That means he needs to make sure offensive security is carried out quickly, easily, and efficiently.

Just weeks after joining the company, Moles had already recognized a broader need to evaluate their attack surface. Even before the prospective customer’s mandate, he needed evidence for an upcoming SOC 2 audit, and clear visibility into the system he’d inherited. He also was tasked with creating a security program from scratch. And since Furl didn’t have an Application Security (AppSec) stack in place to find vulnerabilities and help prevent exploits, he was able to rely on RunSybil for that, as well.

Moles considered going with other cybersecurity companies but ultimately decided on RunSybil because of its cost efficiency, speed, and his trust in the company’s reputation and AI-based abilities.

First Findings in Minutes, Complete Results in Days

Within a few hours of gaining access to the RunSybil platform, Moles had the evaluation up and running.

The scope of the test covered two tenants: the company’s main web app and its internal management tool. Sybil, RunSybil’s autonomous AI agents, ran a black-box pentest, probing endpoints and flagging hundreds of potential vectors that could be exploitable. Working on a live system, the agents searched the external target, which was Furl’s customer-facing authentication flows, for anything that would trigger a script on an internal tool. That kind of cross-tenant script execution could give a bad actor access to the company’s internal data and systems, causing a significant business impact.

Moles noted that an initial finding surfaced in 17 minutes and the full report was done in a matter of days.

“It was a set-it-and-forget-it kind of situation because I just hit a button and could let it run on its own,” says Moles. “I didn’t have to manage people. I didn’t have to manage the operation. It was great because it was so hands-off.”

For Moles, one of the major benefits of using RunSybil was its sheer speed.

“That was just stupid fast,” he says. “We have to find issues and fix them quickly to keep up. Anything I can do to identify and address vulnerabilities faster behooves me. And that’s what we did here. I was impressed by the quick turnaround.”

Sybil’s initial testing found 543 potential issues, but quickly was able to triage that down to three important findings. That filtering, which culled false positives and duplicates, represented a more than 99% noise-reduction from raw signal to validated report. That work alone saved Moles potentially days of manual effort.

Two of the three findings were fixed immediately and one was deemed an accepted risk.

Joseph Moles, CTO and CISO at Furl.ai

“That was just stupid fast. Anything I can do to identify and address vulnerabilities faster behooves me. And that’s what we did here.”

Joseph Moles, CTO and CISO, Furl.ai

‍

“Whenever we can plug any holes we are safer,” says Moles. “And a big value to me is that someone didn’t just hand me more than 500 findings that I needed to go through to find the few important ones. That would have been death by a thousand cuts. Having that distilled down to two or three issues that needed to be addressed took away what would have been a problem. This test gave me a higher level of confidence and one less thing to worry about.”

Before using RunSybil, Furl simply had not had a mechanism in place to identify problems on their attack surface.

That’s no longer the case.

After their point-in-time evaluation worked so well, Furl is now using RunSybil for automated continuous testing of their attack surface. Moles says he wanted a regular cadence of testing because as they grow and add more customers and software to their system, a single, or even periodic, test wouldn’t be enough.

“We need to check the places where changes are being created,” he explains. “If I’m shipping code multiple times a day, we need to be able to look at those deltas. I want to open up that visibility. Make it more indepth. It will give me more confidence about the whole scope of our surface, as well as our code base so I can see if any changes have introduced an exposure. Then I can get anything cleaned up quickly.

“As a one-man-band here, this gives me one less critical thing to worry about,” he adds. “Especially as a security company, it’s important to have active testing with an agent so we have layers of controls and checks.”

Joseph Moles, CTO and CISO at Furl.ai

“It was a set-it-and-forget-it kind of situation because I just hit a button and could let it run on its own. I didn’t have to manage people. I didn’t have to manage the operation.”

Joseph Moles, CTO and CISO, Furl.ai

‍

Scaling a Small Business at the Speed of Growth

Gaining not only that visibility but that extra level of confidence in the security of their attack surface is a relief to a CISO, but it also enables a small business to grow safely. A company’s attack surface expands with each new customer that comes onboard. That means for a startup, what begins as a relatively small attack surface grows exponentially as the business expands, making Moles’ job proportionately harder and more time-consuming.

“Right now our surface is pretty small, but still for one person who has a lot of other tasks to do, it feels a lot bigger,” he says.

And for a small business to grow rapidly, being able to easily and quickly ensure they’re able to scale securely is critical.

“I need our controls and tests to move at the same pace we’re moving as a company so we can maintain the same level of security no matter the rate of our growth,” says Moles. “You have to stay on top of issues before they multiply like gremlins. That enables you to be able to tell your customers that you’re keeping their information safe.”

Derek Abdine, CEO and co-founder of Furl, says this is even more important for Furl.

“When customers are taking a bet on a young company, there isn’t a lot of forgiveness,” he explains. “When there’s a greater level of trust involved, you don’t want to take that for granted.”

That’s even more critical when the business is a security company and it’s building its brand based on reputation.

“We take the trust our customers put in us to protect them, their data, and their systems very seriously,” says Abdine. “We’re shipping new releases every one to three days, so we’re pretty fast. That kind of speed requires an extra level of diligence so we can maintain customer confidence.”

Moles notes that AI is a force multiplier. For good and for bad. Since malicious hackers are using AI to go after their targets, offensive security efforts can’t use blunt-force tools. They need tools as smart, or smarter, than the ones bad actors are using.

He also says he has more confidence in RunSybil, especially from a speed perspective, because it’s AI-based.

“When it comes to cybersecurity, we have to go faster because the attackers are going faster,” Moles explains. “Continuous automated testing is directionally where business needs to go. Anything I can do to stay on top of cybersecurity, identifying and detecting things faster behooves me as a technology leader to do.”

To find out more about RunSybil and how it can protect your organization from cyber attacks