Noise2Signal

Mehul Revankar

A cybersecurity podcast. Cyber conversations with more signal, less Noise. Noise2Signal is the antidote to the cybersecurity echo chamber: unfiltered conversations with the people who actually built the field — no buzzword bingo, no vendor pitches.

  1. 1 day ago

    Ep 18. The CISO before CISO's w/ Scott Crawford

    Scott Crawford's first security job didn't have a name yet. In 1998 he took over digital security at the International Data Center of the Comprehensive Nuclear-Test-Ban Treaty Organization in Vienna—next door to the IAEA, serving 150-odd signatory nations—and the title CISO hadn't been invented. He'd been a commercial pilot in Montana, then went back to grad school, then landed at UCAR in Boulder, where a grapevine of geophysicists pointed him at a job posting so skewed toward physical security that he told the hiring committee what was wrong with it. They hired him anyway. His master's thesis, written on site, was about building a regime of trust in an atmosphere of mutual distrust—which turns out to be a decent description of the next twenty-five years, spent as one of the industry's original analysts and eventually as head of information security research at 451 Research and S&P Global. In this episode, Scott tells Mehul why security is the only technology field where you have to model an adversary who is actively trying to defeat you, why the platform wars are really data-foundation wars, and why he's careful to say models emulate reasoning rather than reason. He also coins a term worth stealing—"Dave Barry's dog syndrome," the model that agrees with every correction you make as if you'd revealed something profound—and gets specific about cyber offense in the age of Mythos and Fable, why the absence of AI-driven exploitation in the wild is a lagging indicator, and where the open-weights fight actually gets decided. Two months into retirement, he's writing his own code, and he thinks the conventional idea of retirement no longer holds for anyone. 00:00:00 Cold open 00:02:40 Pilot, physicist, analyst 00:06:57 Security before the CISO 00:12:49 Platformization and the data puddles 00:23:25 Confidently incomplete 00:34:19 Offense in the age of AI 00:40:06 The price of poor hygiene 00:44:27 Placing bets, and the token bill 00:47:48 Open weights, and who vets the vetters 00:56:28 Retirement, and the human on the loop

  2. 1 Sept

    Ep 17. 0 to 1 on EPSS w/ Jay Jacobs. Chief Data Scientist at Empirical Security

    Jay Jacobs didn't set out to rewrite vulnerability prioritization—he set out to keep working on data he loved. After helping build Verizon's DBIR alongside Wade Baker, the two spun up Cyentia Institute to do the same kind of research without Verizon attached to it. Two of Cyentia's earliest customers happened to be holding opposite halves of the same puzzle: Kenna had scan data and vulnerability sightings across hundreds of companies, and Fortinet had detections of what attackers were actually exploiting. "What if we bring this together?" turned into a side experiment, then a Black Hat paper, then EPSS—and eventually into Empirical Security, where Jay is Chief Data Scientist to give the score a permanent home. In this episode, Jay tells Mehul the full arc: why only two to five percent of vulnerabilities ever get exploited and what broke his "food supply" theory of attacker behavior, why CVSS is really measuring a practitioner's perception of how bad a vector string looks, the delicate conversations at Kenna about giving away a proprietary score, and the naming theory behind making "EPSS" rhyme with the thing it was replacing. He also gets specific about the machinery—why Metasploit is a strong signal and Exploit-DB is a weak one, why nobody hand-assigns weights, where the "23% more accurate" stat in v5 actually comes from—and closes with the gun-to-the-head threshold answer that surprises almost everyone who hears it: not 0.9, but 0.03. In our in-depth discussion, Jay shares: 00:03:19 — Jay Jacobs, Cyentia, and the Side Project That Became EPSS 00:06:53 — The 2–5% Number and What CVSS Actually Measures 00:13:11 — Why EPSS Had to Be Given Away 00:18:01 — Building the Model 00:24:07 — Grading the Model in Public 00:29:45 — EPSS v5 and Where "23% More Accurate" Comes From 00:35:27 — Who Funds It and Who's Using It 00:41:13 — AI-Written Exploits 00:46:37 — The Number for the Frustrated CISO

  3. 1 Jul

    EP 12. Building Companies, Culture, & Cyber Offense and Defense in the Age of AI w/ Ron Gula'

    Ron Gula is a cybersecurity pioneer, venture capitalist, and the visionary founder behind Tenable. Having bootstrapped his way to a $50 million Series A and scaled one of the industry's most recognizable brands, Ron has witnessed the highs and lows of company building. In this episode, we explore the authentic culture he established during Tenable's early days, the critical mistakes founders make when pitching venture capital, and the shifting landscape of building startups in the AI era. Ron details the strict rules of his famous "five-slide pitch deck," explains why AI wrappers are simply integrators rather than innovators, and warns that CISOs must take charge of AI operations before they are replaced by automated platforms. In our in-depth discussion, Ron shares: [00:04:21] Shaping Tenable's early culture with Cyndi Gula and Renaud Deraison. [00:08:10] Offering a junior employee a 4-day workweek during the 2008 crisis. [00:09:55] Talking a customer out of buying unneeded vulnerability scanners. [00:17:05] Creating "V-Ron," an unfiltered 3D avatar for controversial opinions. [00:22:44] Secondary sales that enrich employees versus traditional VC rounds. [00:24:51] Why sub-$1M ARR startups raising $30M rounds is a major red flag. [00:27:15] The strict "five-slide pitch deck" methodology to secure funding. [00:35:08] Pitching mistakes: leading with advisor names instead of solutions. [00:37:51] The danger of AI wrappers: becoming an integrator, not an innovator. [00:45:56] The impending platformization and consolidation of cybersecurity. [00:52:34] Predicting the replacement of CISOs by AI operations and MSSPs. [00:52:58] Why CISOs must aggressively lobby to run internal AI operations. [00:57:40] Why cyber hygiene fails against nation-states, requiring air gaps. [00:59:25] The economic realities of rising ransomware costs and falling payouts. [01:04:23] The future of AI-Native offense and Defense

About

A cybersecurity podcast. Cyber conversations with more signal, less Noise. Noise2Signal is the antidote to the cybersecurity echo chamber: unfiltered conversations with the people who actually built the field — no buzzword bingo, no vendor pitches.

You Might Also Like