Down the Security Rabbithole Podcast (DtSR)

Rafal (Wh1t3Rabbit) Los

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show.On Twitter/X: https://twitter.com/@DtSR_PodcastOn YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqOn LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/

  1. 2d ago

    DtSR Episode 721 - Finance Masterclass for Cyber (Part 2)

    TL;DR: This pod is part 2 of a 2-part series in which Patrick shares his insights on the world of finance as it relates to cyber startups and financing. As promised, the tracksuit shows up, and it's an epic episode! Guest: Patrick Dennis Description Private equity can feel like a plot twist: one day you are celebrating growth, the next day you are hearing new words like EBITDA, leverage, recap, and “value creation plan,” and everything from headcount to product scope is suddenly under a microscope. We sit down with Patrick to explain what is actually happening behind the scenes when a cybersecurity company moves from venture-backed momentum into private equity discipline. We start with a clean breakdown of venture capital vs private equity. VC funds can afford many misses because a few massive outcomes pay for everything, whereas PE makes fewer investments and needs them to work more reliably. That difference shapes company behavior, especially when “grow at all costs” collides with a finite market, customer concentration, and the hard truth that bookings and ARR only matter if they turn into cash. Then we demystify the metrics and mechanics that operators keep hearing but rarely get explained: why cash flow becomes the real governor, why EBITDA becomes the shared language among management, lenders, and investors, and how a value-creation plan drives changes in spend, pricing, and operating discipline. We also get candid about the darker fork in the road: down rounds, running out of cash, taking on debt through leveraged buyouts, and what happens when a company cannot service interest, and lenders end up in control. Finally, we map the exit paths and what they mean for employees: IPO vs strategic sale vs sponsor-to-sponsor trades, plus how cash and stock deals can (and cannot) translate into payouts for option holders. If you want to evaluate your company’s trajectory with clearer eyes, subscribe, share this with a teammate, and leave a review with the finance term you want us to unpack next. Youtube Video: https://www.youtube.com/live/3YfiJiTdLhk?si=oiGXZVhHofb3ijnk Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

  2. Aug 25

    DtSR Episode 720 - Finance Masterclass for Cyber (Part 1)

    TL;DR: This week's pod features a Masterclass on finance for Cyber folks, led by Patrick Dennis, where we ask all kinds of questions and go from idea to the pre-growth stage of a company. What's next? Check out part 2 coming next. Guest: Patrick Dennis Description A splashy funding announcement can feel like proof you’re winning, but it can also be the moment the clock gets louder. We sit down with returning guest Patrick Dennis, a multi-time [cybersecurity] CEO and operator who “swims in these waters,” to translate the funding ecosystem into plain English and remove the mystique from venture money without dumbing it down. If you’ve ever wondered why a Series D gets celebrated, what that really signals, and what it costs later, this conversation is for you. We walk step-by-step through the early-to-late funding path: angel investors and seed rounds, venture capital at Series A and B, growth equity, and how private equity can show up as companies scale. Along the way, we tackle the words people throw around at conferences as if they’re obvious: valuation, dilution, burn rate, cap table, down rounds, and liquidity. Patrick breaks down why valuation is largely “on paper” until an exit, why investor timelines often point to a three-to-seven-year window, and why the higher you push the price, the smaller your list of realistic buyers becomes. We also talk about the “markup” incentive system that can quietly trap teams into needing a bigger round or a bigger exit than the market will support. Then we bring it back to operating reality: how the zero-interest-rate [ZIRP] era trained cybersecurity companies to spend aggressively, and what changes when money is no longer cheap. We close with the human part founders underestimate most: taking money means giving up control and choosing a partner, and “hands-off” becomes “hands-on” fast when performance slips. Subscribe for part two, share this with a founder or operator in your circle, and leave a review with the funding question you want answered next. YouTube video: https://youtube.com/live/zbDNnbHKEaU Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

  3. Aug 18

    DtSR Episode 719 - Budget Season for CISOs

    Guests Jack KorzeniowskiKen FosterTL;DR: Budget season is upon us, and Rafal & James sit down with Ken Foster and Jack Korzeniowski to get some insights into how CISOs deal with budgets, separate truth from fiction, and get down into the dirty secrets. Description Budget season can feel like a slow-motion incident response: everyone has competing priorities, nobody wants surprise spend, and security still has to defend the enterprise. We sit down with experienced security leaders to talk candidly about how cybersecurity budgeting really works when you’re fighting for headcount, renewals, and new controls while leadership asks for ROI and says, “Nothing’s happened for three years, so why are we spending so much?” We share what actually lands in a budget deck that survives scrutiny and what gets cut even when it is clearly needed.  From there, we get practical about the messy realities that break a clean plan. Audit findings can free up money faster than any risk narrative, but relying on that is a terrible strategy, so we discuss how to model “what happens if we don’t renew” and how to translate risk tolerance into finance language. We also dig into surprise drivers like mergers and acquisitions, sudden asset growth, and cross-team dependencies, where security buys the tool, but IT and app teams handle deployment and ongoing operational workload. If you don’t align early, you don’t just miss timelines; you damage trust across the organization.  Then we tackle the newest budget collision: AI. Tokenomics, unpredictable utility bills, rising infrastructure costs, shadow AI, and rapidly forming “AI debt” can turn a reasonable forecast into a painful true-up. We outline ways to cap spend, phase rollouts, and keep governance tight without killing innovation. Finally, we give vendors and consultants a clear playbook for being better partners: multi-year price predictability, phased licensing, honest roadmap commitments, no surprise true-ups, and real total cost of ownership and ROI modeling that helps us sell the work internally.  If you found this useful, subscribe, share it with a security leader heading into budget season, and leave a review with the one budget surprise you never want to relive. Youtube Video: https://youtube.com/live/al7gQvb7C_Q Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

  4. Aug 11

    DtSR Episode 718 - Black Hat Recap And The Rush To Rebrand Everything

    Guest: Dr. Chase "ZeroTrust" Cunningham TL;DR: AI Marketing slop took over Black Hat Las Vegas 2026, and Rafal sits down for a one-on-one with Chase Cunningham. Featuring their patented level of snark, real analysis, and hype detection, it's a fun conversation. Description Black Hat is supposed to be where the security industry shows its best work. This year, it also showed its biggest temptation: slap “AI” on everything, crank the volume, and sort out the truth later. We break down what we saw on the floor and what it says about cybersecurity right now, with Chase Cunningham (Dr. Zero Trust) bringing receipts from vendor go-to-market changes and the money flowing into “AI-first” security startups. We talk about why so many tools sound identical, how “AI infrastructure” became the new catch-all label, and why the word “leader” stops meaning anything when everyone uses it. Then we get practical: how do you ask a booth team to define their artificial intelligence, what counts as autonomy, and what answers should make you walk away? The conversation gets real when “AI security” turns out to be a polished UI sitting on top of a large language model API call. We dig into vendor lock-in, pricing and subsidy risk, and the uncomfortable question of who eats the impact when model providers change costs or terms. From there we go straight at the hottest promise in security operations: autonomous SOC and agent swarms. Non-deterministic models can be useful, but mistakes at machine speed can turn into outages and bad calls, so we map where automation helps and where humans still matter. We also call out what we didn’t see: serious talk about hiring, growing junior talent, or serving SMB security needs even though many breaches flow through third parties and smaller vendors. If you care about security outcomes more than security slogans, this one’s for you. Subscribe, share, and leave a review, then tell us: what’s the most inflated AI claim you’ve heard lately? YouTube video: https://youtu.be/mww1YpP-J0k Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

  5. Aug 4

    DtSR Episode 717 - Your UI is B******t

    Guests: Michael Farnum, Sam Van Ryder TL;DR: Most cybersecurity dashboards don’t fail because they’re ugly. They fail because they don’t change what we do next. Description In Episode 717, Rafal sits down with Michael Farnum (Cybersec Community) and Sam (Dragos, a long-time OT and industrial cybersecurity practitioner) to talk about the uncomfortable truth behind security UI/UX: much of what shows up in the GUI is pure noise. We dig into the split between “pretty but useless” interfaces and tools that are practical but painful, then map out what a real practitioner-focused dashboard should deliver: contextual metrics, clear workflows, and data that drives action inside a SOC, an MDR, or an enterprise security team. From SIEM and EDR lessons to product management realities, we unpack why companies miss the mark when marketing drives the roadmap or when engineering builds for engineers only. We also get candid about the analyst ecosystem, the difference between grounded practitioner feedback and “ivory tower” trend-chasing, and how that can steer executives toward tools that are hard to operationalize. Then we move into AI and CTEM, continuous threat exposure management, and why the win isn’t a flashier interface. The win is faster telemetry correlation, so we can answer the questions that matter: is this vulnerability reachable in our environment, is it exploitable, and what should we prioritize right now? We also touch on modern “interfaces” like APIs and MCP, where the UX becomes how efficiently you can get results, even when the user is another machine. If you care about security tools that actually work under pressure, hit play, subscribe, share the episode with a teammate, and leave a review with your biggest UI pet peeve. YouTube Video: https://youtube.com/live/ts2rU1-j4EI Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

  6. Jul 28

    DtSR Episode 716 - What if Context Replaced Alerts Entirely

    Guests: Jason Vest & Josh Neil TL;DR: Alert fatigue is still a problem; detection isn't generationally better - but we have all this AI. So what gives? Description Alert fatigue is not just a workload problem; it is a product design problem. We dig into a provocative claim sparked by a LinkedIn post: today’s “AI SOC triage” can be a band-aid if it only cleans up alerts after the fact instead of improving threat detection where it starts, in raw telemetry and early signal extraction. We’re joined by Jason Vest (CTO at Binary Defense) and Josh (a statistician with experience from Los Alamos, the Department of Energy, and leading the Microsoft Defender for Endpoint data science team). Together we unpack why rules and detection engineering still matter: they encode what we know is bad, but rigid rule matches and atomic alerts can also trap teams in an endless false positive vs. false negative trade-off. Josh goes as far as to argue that alerts should “die in a fire,” pushing us to think in terms of attack stories and enterprise-wide context, not isolated hits. From there we explore what actually scales: when anomaly detection works, why “model everything” breaks down, and how trigger-based just-in-time modeling can build lightweight models on demand, score the nearby context, then disappear. We also talk about moving from alerts to “situations,” using agentic AI to gather more context across identity, endpoint, and network, plus what transparency should look like for model validation and community standards. Subscribe, share this with your SOC team, and leave a review. Where do you think detection should evolve next: better rules, better models, or a world without alerts? YouTube Video: https://youtube.com/live/GYjePXCiKM0 Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

4.3
out of 5
95 Ratings

About

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show.On Twitter/X: https://twitter.com/@DtSR_PodcastOn YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqOn LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/

You Might Also Like