The Signal

Seven member companies in five industries opened testing decisions this month. They span four categories: continuous penetration testing, exploitability proof, AI-code security, and test automation. All four answer one question. Can you prove this is reachable?

Eight of those ten decisions landed in four business days, August 21 through August 24. Six separate companies. Two are past browsing. Both are in active evaluation, both attached a timeline, and both named themselves the decision maker.

The pattern is not more vulnerabilities. It is a findings list that stopped carrying weight. A CISO in Software put the mechanism plainly in his submission to the DoGood network. Exploitability is now the argument between security and application engineering. Not severity. Not volume. Whether an attacker can reach the thing.

That changes what these leaders are shopping for. A scanner sells findings. These seven are buying evidence.

From the Network

"Most of the time exploitability of the vulnerability comes as a question and becomes a constraint in between security and app engineering, and in case of vended product, vendor and engineering. Looking for a demonstrable way to show exploitability."

— Chief Information Security Officer, Software

"Evaluating options to reduce risk and vulnerabilities across the environment. Looking for automated solutions to reduce time to remediation, in light of reduced timeline to exploit."

— Director, Information Security, Finance

"Currently we use all flavors of AI systems in our dev environment, and quickly AI governance and risk management is becoming a concern."

— Senior Vice President and CISO, Business Services

AI is writing more of the code. The exploit window keeps closing. The proof burden landed on security, and all three of these leaders are buying against it.

Top Open Priorities This Week

Two raw asks pulled directly from member submissions in the last 14 days, unedited:

"We are always doing pentesting but it's only point in time. Is there a way to do routinely without breaking the bank? This way we can proactively do these meaningful tests."

— Senior Director, IT Infrastructure Operations and Cybersecurity, Hospitality

"I want to understand how depthfirst uses agentic AI to find and remediate exploitable vulnerabilities, compares with SAST/SCA tools, integrates with CI/CD workflows, reduces false positives, protects source code, and demonstrates measurable ROI."

— Chief Information Security Officer, Finance

Both are asking for the same two properties in different words: continuous, and provable. Point-in-time testing and a false-positive-heavy queue are the failure modes they name.

Member Spotlight: Michael Dawisha, Genesee County, Michigan

This week's Signal is about proving the work rather than asserting it, which is a fight Michael Dawisha picked early. He is now CIO of Genesee County, Michigan, and he ran into the gap at a nonprofit whose mission he believed in, "It's an honorable mission that I thought was really something beautiful. But what they didn't do is utilize any kind of science to measure their services."

The Context

The headlines are catching up to what the network already knew. Veracode published its 2026 GenAI Code Security Report on July 28. The average security pass rate for AI-generated code came in at 56 percent. The number is not the story. The breakdown is.

Models passed SQL injection tests 83 percent of the time and cryptography 87 percent. They passed cross-site scripting 15 percent of the time and log injection 12 percent. The failures cluster in the classes where severity depends on whether the path is reachable at all. Veracode's own summary of the result: "syntax is solved, security is not."

Bottom Line: The classes AI code fails hardest are the ones a scanner cannot rank for you, which is why proof of reachability is what members are now willing to pay for.

What to Do About It

Pull your last two penetration test reports and count how many findings were re-tested after remediation, not just marked closed. Then ask your application security lead which open criticals are reachable from the internet today. If that answer takes longer than an afternoon, you have found the gap.

The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT leader at a $100M+ company? Apply to join DoGood.