Maciek Palmowski from Patchstack discusses research testing whether 'secure hosting' claims by WordPress hosting providers hold up under real penetration testing. Using 30 known plugin vulnerabilities across multiple hosts with standardized methodology, they found 70-80% of WordPress-specific attacks succeeded. Key findings: hosts using identical security tools produced drastically different results (configuration matters more than tooling), generic security layers perform well but WordPress-specific attacks largely bypass them, and 50% of discovered vulnerabilities were unpatched at time of disclosure. The conversation covers the Swiss cheese model of layered security, the danger of bold marketing claims, AI accelerating attack timelines (exploitation now begins within 5 hours of disclosure), and practical questions to ask hosting providers about WordPress-aware security solutions.