ZeroSum

Aaron Mog

ZeroSum is a new cybersecurity podcast that aims to talk honestly about the state of the cybersecurity industry. The show rejects standard "threat of the week" news breakdowns and instead focuses on the reality of the market. Viewing the industry through the lens of game theory, the podcast explores how the current cyber market is no longer a rising tide that lifts all boats; for massive VC gambles to win, the burnt-out practitioners on the ground are often the ones losing. The show features guests from all perspectives, including vendors, investors, workers, and CISOs.

Episodes

  1. 3 days ago ·  Video

    AI Is Better at Hacking Than He Is, and He's Not Worried - with Scott Behrens

    He's an L8 Principal Engineer at Netflix — the kind of technical leader the company puts on the problems that decide whether it wins or loses. And he just watched AI out-hack him. Scott Behrens is an L8 Principal Security Engineer at Netflix, where over 11 years he's watched the security team grow from a handful of people to over a hundred. Today he's the technical lead for Netflix's Live product security, its Attack Emulation Red Team, and its DDoS research. He joins Aaron for one of the most honest, forward-looking conversations we've had about what AI actually does to security work, and to the people who do it. Scott doesn't sugarcoat it: he sat down with the latest models and quickly concluded they're better at finding and exploiting vulnerabilities than he is. But instead of doom, he lays out why that's an opportunity and where humans still hold the irreplaceable edge. We get into why the model matters less than the "harness" you build around it, the idea that human intention and hard-won wisdom are the most valuable resources in the AI race, and what actually happens when your discovery tools start surfacing thousands of real vulnerabilities you now have to fix. Plus: how AI is quietly making security the easiest story he's ever had to tell, the one-line trick that cuts vulnerabilities in AI-written code, and why the best security engineers are becoming systems thinkers, not bug-finders. Guest: Scott Behrens, L8 Principal Security Engineer at Netflix. Find him on LinkedIn and read his newsletter, The Engineer Setlist, on Substack. ⏱️ CHAPTERS 00:00 Intro 01:57 Excited, worried, and humbled all at once 04:16 Don't just do the old things faster 07:30 Should security teams fix the bugs, not just find them? 09:30 Human intention is the most valuable resource in the AI race 10:16 The "wisdom" AI doesn't have 12:22 Systems thinking as the human edge 18:14 Why the harness matters more than the model 20:25 Codifying 20 years of expertise into a harness 23:41 You built the harness — now what do you do with the findings? 25:32 What small and mid-size businesses should actually do 27:35 The one-line trick that cuts vulnerabilities in AI code 30:41 Rethinking the front end, WAFs, and detection 32:45 The "isadmin=false" honeypot trick 51:50 The era of YOLO security 53:09 Security as an enablement function 55:04 "The easiest story I've ever had to tell" 56:34 Where to find Scott #cybersecurity #infosec #AI #Netflix #appsec

  2. 5 days ago ·  Video

    Why Security Always Failed and What Finally Changes That - with Justin Somaini

    For 30 years, the security industry could never fully win. Justin Somaini explains what finally changes that. Justin Somaini is one of the people who helped define the modern CISO role — former CISO of Symantec, Yahoo, SAP, and Box, and now a Partner at YL Ventures. In this episode, Aaron sits down with him for a genuinely optimistic conversation about why security has always fallen short, and why he believes we're at the most exciting inflection point in the industry's history. Justin lays out his core thesis: security has never truly succeeded because of two structural problems — you can never hire enough people to review everything, and the industry never solved the "shared accountability" gap with engineering and IT. For the first time, he argues, AI can absorb the enormous amount of pattern-matching work that's always overwhelmed security teams — letting them finally operate at the scale the business actually demands. We also get into how he learned to separate real founders from the hype (and the belief he had to unlearn), why "drop the first slide" is his number one pitch advice, how CISOs actually make buying decisions versus what they claim, and his honest take on where the funding market is heading. Plus: the first CISO ever, why word-of-mouth beats every marketing tactic, and what makes a startup worth betting on. Guest: Justin Somaini, Partner at YL Ventures. Find him on LinkedIn or on his podcast, Somaini Trust Issues. ⏱️ CHAPTERS 00:00 Intro 01:38 Learning from Steve Katz, the first CISO ever 04:03 Why a 30-year veteran is optimistic right now 05:23 Why security has always failed — the two real reasons 07:42 How AI absorbs the work that overwhelms security teams 10:03 How to separate real founders from the hype 13:13 Salesperson, or a product engineer faking it? 16:15 "Drop the first slide" — fixing the founder pitch 18:20 Why first-time founders are like teenagers 22:10 The funding market and where it's headed 28:12 Need-to-have vs. nice-to-have 36:42 How CISOs actually make buying decisions 52:00 How to get anyone to care about what you're building 57:04 Where to find Justin

  3. 22 Jul ·  Video

    The Haystack Got Bigger. The Needles Didn't - with Ed Bellis

    The haystack got bigger. The needles didn't. Ed Bellis on why the vulnerability problem stopped being human-scale. Ed built Kenna Security, sold it to Cisco, and is now back with Empirical Security, building custom AI models that predict which vulnerabilities will actually get exploited in your environment — not just which ones score high on a generic global list. He joins Aaron for a candid conversation about what AI is really doing to the vulnerability landscape, the security talent pipeline, and the funding environment. We cover why AI is producing more code than ever and more vulnerable code than ever, what Anthropic told him about not hiring junior devs anymore ("what happens when the seniors time out?"), why every organization needs a model trained on its own environment, and where startups still win against Microsoft and Google. Plus: why raising $180M in a seed round quietly kills your optionality, the "fast no," and the Chicago startup problem. Guest: Ed Bellis, CEO of Empirical Security → empiricalsecurity.com ⏱️ CHAPTERS 00:00 Intro 01:20 Coming off a raise — what it actually changes 03:22 What money doesn't fix 05:02 The mistakes he won't repeat from Kenna 07:47 Why a huge seed round kills your optionality 09:03 Is private equity coming for cyber? 12:48 Why every company needs its own model 17:22 Is it just YOLO security now? 18:28 The haystack got bigger, the needles didn't 20:25 AI, remediation, and operational risk 23:45 Anthropic doesn't hire junior devs anymore 26:19 If you take the bottom rung out of a ladder 30:42 Advice for a 22-year-old entering cyber 32:57 Cutting through the noise at Black Hat 36:47 Why he loves a "fast no" 37:26 The Chicago startup problem 39:22 Where startups fit against Microsoft and Google 43:47 Build vs. buy: should you train your own models? 49:02 Where to find Ed #cybersecurity #infosec #AI #vulnerabilitymanagement #startups

About

ZeroSum is a new cybersecurity podcast that aims to talk honestly about the state of the cybersecurity industry. The show rejects standard "threat of the week" news breakdowns and instead focuses on the reality of the market. Viewing the industry through the lens of game theory, the podcast explores how the current cyber market is no longer a rising tide that lifts all boats; for massive VC gambles to win, the burnt-out practitioners on the ground are often the ones losing. The show features guests from all perspectives, including vendors, investors, workers, and CISOs.