top of page
Search

Filigran CTO on Building an Award-Winning, AI-Native Threat Management Platform

  • 2 days ago
  • 3 min read

Filigran was recently recognized with the Most Innovative Security Solution award for its eXtended Threat Management (XTM) Platform, an open, AI-native ecosystem that unifies threat intelligence, adversarial exposure validation, and risk governance. We sat down with Julien Richard, CTO and Co-Founder of Filigran, to talk about the company's mission and how the XTM Platform is helping security teams move from reactive alert-chasing to continuous, threat-informed defense.


Julien Richard, CTO and Co-Founder of Filigran

For readers who may not be familiar with Filigran, can you introduce the company and what it does? 


A: Filigran is a European company, founded in 2022 by our CEO, Samuel Hassine, and me. We started the company because we saw the same gap everywhere: security teams had more tools and more data than ever, but no real way to turn that into fast, confident action. Our mission is to empower defense teams to be proactive through open-source solutions that uncover threats and drive action. We began with OpenCTI, a platform to centralize and structure threat intelligence, and have since expanded into OpenAEV for continuous exposure validation, with OpenGRC (risk governance and quantification) coming next. Together, these form our XTM Platform. At its center is XTM One, an agentic AI layer that connects intelligence, validation, and response into one workflow. Everything we build starts as open source. We're backed by a global community of more than 6,500 practitioners who build alongside us. 


What's the biggest challenge you see security teams facing today? 


A: It isn't a lack of data. Organizations have more visibility into their environments than ever. The real challenge is separating signal from noise. A large security team can receive thousands of alerts a day, but only a small fraction of them represent a genuine, exploitable threat. Our State of Threat Management report found that security teams spend an average of 42% of their time investigating risks that later prove low priority or non-exploitable. In a 40-hour week, that's about 17 hours per analyst. That's not just an efficiency problem. It's a retention problem, and it hits some of the most skilled people in the industry. 


How does the XTM Platform help organizations address that problem? 


A: We help organizations move from reactive to proactive security, following what the industry calls CTEM: Continuous Threat Exposure Management. Instead of a point-in-time assessment, it's a continuous cycle: understand the threat landscape, prioritize the exposures that actually matter to you, validate whether your defenses hold up against realistic attacks, and act on what you find. Then repeat. That's exactly what our platform is built to deliver. Being secure today doesn't mean you're secure tomorrow. Threats evolve, and systems change, so defenses need to be tested continuously, not once a year during an audit.


What role does AI play in Filigran's approach? 


A: AI helps teams keep pace with the volume and speed of modern threats, but the goal isn't to replace the analyst. It's to remove the low-value work that keeps analysts from focusing on what matters. Through XTM One, teams can ask direct questions of their own data, automate repetitive investigation steps, and get straight to the context they need, while humans stay in control of the decisions that count. The point of AI here isn't automation for its own sake. It's giving skilled people back the time to do the work only they can do. 


Why is open source such a core part of Filigran's model? 


A: Cybersecurity is built on trust, and trust requires transparency. When your security stack is open source, you can see exactly how it works, adapt it to your environment, and keep control of your own data. That matters enormously for organizations handling sensitive information, and increasingly for anyone thinking about digital sovereignty and long-term control of their systems. It also means we build alongside our community of practitioners and contributors instead of behind closed doors. That community is a big part of why our products keep improving as fast as the threat landscape does. 


What's next for Filigran, and what excites you most right now? 


A: We're focused on closing the gap between knowing about a risk and acting on it in time. That means connecting threat intelligence, exposure validation, and, risk governance and quantification. The goal is for security and business leaders to finally work from the same picture instead of several disconnected ones. What excites me most is that this isn't just a technology shift. It's a mindset shift, from managing alerts to managing outcomes. The organizations that make that shift are the ones that will actually get ahead of attackers, instead of constantly chasing them.

 
 
bottom of page