Noise2Signal

Mehul Revankar

A cybersecurity podcast. Cyber conversations with more signal, less Noise. Noise2Signal is the antidote to the cybersecurity echo chamber: unfiltered conversations with the people who actually built the field — no buzzword bingo, no vendor pitches.

  1. Sep 29

    Ep. 21 Seven Samurai's of VulnOps & Dead Men (SaaS?) Walking w/ Nico Popp

    Nico Popp, operating partner at Crosspoint Capital Partners and former Chief Product Officer at Tenable, joins Mehul to explain why he came back from Black Hat saying there were "dead men walking everywhere." He argues that putting AI on top of a legacy product doesn't make it AI-native. The real shift is a new architecture: sensors feed a context graph, the graph feeds a reasoning layer, and agents sit on top where the console used to be. They cover what makes a durable moat now ("the three musketeers": agentic architecture, captured agent trajectories, and your own reinforcement-learned models), why wiring in frontier models is a strategic blunder, and Nico's "Seven Samurai" framework for VulnOps. That framework describes how vulnerability management has to change when attackers are agentic, and why it ends up absorbed into the agentic SOC. Along the way they discuss the Cisco–Kenna and ServiceNow–Armis deals, the future of the console UI and what happens to entry-level security jobs. Chapters 00:00 Welcome and introductions 01:17 Black Hat, "dead men walking," and why every company is now legacy 03:24 What AI-native really means: sensors → context → reasoning → agents 07:20 SaaSpocalypse or SaaS renaissance? The case against building on frontier models 12:54 Building moats in the age of AI: the three musketeers 19:09 "Agentic" everything, platformization, and where CTEM goes 23:46 VulnOps and the Seven Samurai: shift left, appliances and continuous scanning 38:21 Validation, prioritization, and the Kenna and Armis acquisitions 50:36 Agentic patching, virtual patching and the federated agentic SOC 1:00:02 Hot takes: the death of the console, AI labs vs. cyber vendors, and CTEM's future

  2. Sep 9

    Ep 18. The CISO before CISO's w/ Scott Crawford

    Scott Crawford's first security job didn't have a name yet. In 1998 he took over digital security at the International Data Center of the Comprehensive Nuclear-Test-Ban Treaty Organization in Vienna—next door to the IAEA, serving 150-odd signatory nations—and the title CISO hadn't been invented. He'd been a commercial pilot in Montana, then went back to grad school, then landed at UCAR in Boulder, where a grapevine of geophysicists pointed him at a job posting so skewed toward physical security that he told the hiring committee what was wrong with it. They hired him anyway. His master's thesis, written on site, was about building a regime of trust in an atmosphere of mutual distrust—which turns out to be a decent description of the next twenty-five years, spent as one of the industry's original analysts and eventually as head of information security research at 451 Research and S&P Global. In this episode, Scott tells Mehul why security is the only technology field where you have to model an adversary who is actively trying to defeat you, why the platform wars are really data-foundation wars, and why he's careful to say models emulate reasoning rather than reason. He also coins a term worth stealing—"Dave Barry's dog syndrome," the model that agrees with every correction you make as if you'd revealed something profound—and gets specific about cyber offense in the age of Mythos and Fable, why the absence of AI-driven exploitation in the wild is a lagging indicator, and where the open-weights fight actually gets decided. Two months into retirement, he's writing his own code, and he thinks the conventional idea of retirement no longer holds for anyone. 00:00:00 Cold open 00:02:40 Pilot, physicist, analyst 00:06:57 Security before the CISO 00:12:49 Platformization and the data puddles 00:23:25 Confidently incomplete 00:34:19 Offense in the age of AI 00:40:06 The price of poor hygiene 00:44:27 Placing bets, and the token bill 00:47:48 Open weights, and who vets the vetters 00:56:28 Retirement, and the human on the loop

  3. Sep 1

    Ep 17. 0 to 1 on EPSS w/ Jay Jacobs. Chief Data Scientist at Empirical Security

    Jay Jacobs didn't set out to rewrite vulnerability prioritization—he set out to keep working on data he loved. After helping build Verizon's DBIR alongside Wade Baker, the two spun up Cyentia Institute to do the same kind of research without Verizon attached to it. Two of Cyentia's earliest customers happened to be holding opposite halves of the same puzzle: Kenna had scan data and vulnerability sightings across hundreds of companies, and Fortinet had detections of what attackers were actually exploiting. "What if we bring this together?" turned into a side experiment, then a Black Hat paper, then EPSS—and eventually into Empirical Security, where Jay is Chief Data Scientist to give the score a permanent home. In this episode, Jay tells Mehul the full arc: why only two to five percent of vulnerabilities ever get exploited and what broke his "food supply" theory of attacker behavior, why CVSS is really measuring a practitioner's perception of how bad a vector string looks, the delicate conversations at Kenna about giving away a proprietary score, and the naming theory behind making "EPSS" rhyme with the thing it was replacing. He also gets specific about the machinery—why Metasploit is a strong signal and Exploit-DB is a weak one, why nobody hand-assigns weights, where the "23% more accurate" stat in v5 actually comes from—and closes with the gun-to-the-head threshold answer that surprises almost everyone who hears it: not 0.9, but 0.03. In our in-depth discussion, Jay shares: 00:03:19 — Jay Jacobs, Cyentia, and the Side Project That Became EPSS 00:06:53 — The 2–5% Number and What CVSS Actually Measures 00:13:11 — Why EPSS Had to Be Given Away 00:18:01 — Building the Model 00:24:07 — Grading the Model in Public 00:29:45 — EPSS v5 and Where "23% More Accurate" Comes From 00:35:27 — Who Funds It and Who's Using It 00:41:13 — AI-Written Exploits 00:46:37 — The Number for the Frustrated CISO

Ratings & Reviews

5
out of 5
2 Ratings

About

A cybersecurity podcast. Cyber conversations with more signal, less Noise. Noise2Signal is the antidote to the cybersecurity echo chamber: unfiltered conversations with the people who actually built the field — no buzzword bingo, no vendor pitches.