Noise2Signal

Mehul Revankar

A cybersecurity podcast. Cyber conversations with more signal, less Noise. Noise2Signal is the antidote to the cybersecurity echo chamber: unfiltered conversations with the people who actually built the field — no buzzword bingo, no vendor pitches.

  1. Sep 9

    Ep 18. The CISO before CISO's w/ Scott Crawford

    Scott Crawford's first security job didn't have a name yet. In 1998 he took over digital security at the International Data Center of the Comprehensive Nuclear-Test-Ban Treaty Organization in Vienna—next door to the IAEA, serving 150-odd signatory nations—and the title CISO hadn't been invented. He'd been a commercial pilot in Montana, then went back to grad school, then landed at UCAR in Boulder, where a grapevine of geophysicists pointed him at a job posting so skewed toward physical security that he told the hiring committee what was wrong with it. They hired him anyway. His master's thesis, written on site, was about building a regime of trust in an atmosphere of mutual distrust—which turns out to be a decent description of the next twenty-five years, spent as one of the industry's original analysts and eventually as head of information security research at 451 Research and S&P Global. In this episode, Scott tells Mehul why security is the only technology field where you have to model an adversary who is actively trying to defeat you, why the platform wars are really data-foundation wars, and why he's careful to say models emulate reasoning rather than reason. He also coins a term worth stealing—"Dave Barry's dog syndrome," the model that agrees with every correction you make as if you'd revealed something profound—and gets specific about cyber offense in the age of Mythos and Fable, why the absence of AI-driven exploitation in the wild is a lagging indicator, and where the open-weights fight actually gets decided. Two months into retirement, he's writing his own code, and he thinks the conventional idea of retirement no longer holds for anyone. 00:00:00 Cold open 00:02:40 Pilot, physicist, analyst 00:06:57 Security before the CISO 00:12:49 Platformization and the data puddles 00:23:25 Confidently incomplete 00:34:19 Offense in the age of AI 00:40:06 The price of poor hygiene 00:44:27 Placing bets, and the token bill 00:47:48 Open weights, and who vets the vetters 00:56:28 Retirement, and the human on the loop

  2. Sep 1

    Ep 17. 0 to 1 on EPSS w/ Jay Jacobs. Chief Data Scientist at Empirical Security

    Jay Jacobs didn't set out to rewrite vulnerability prioritization—he set out to keep working on data he loved. After helping build Verizon's DBIR alongside Wade Baker, the two spun up Cyentia Institute to do the same kind of research without Verizon attached to it. Two of Cyentia's earliest customers happened to be holding opposite halves of the same puzzle: Kenna had scan data and vulnerability sightings across hundreds of companies, and Fortinet had detections of what attackers were actually exploiting. "What if we bring this together?" turned into a side experiment, then a Black Hat paper, then EPSS—and eventually into Empirical Security, where Jay is Chief Data Scientist to give the score a permanent home. In this episode, Jay tells Mehul the full arc: why only two to five percent of vulnerabilities ever get exploited and what broke his "food supply" theory of attacker behavior, why CVSS is really measuring a practitioner's perception of how bad a vector string looks, the delicate conversations at Kenna about giving away a proprietary score, and the naming theory behind making "EPSS" rhyme with the thing it was replacing. He also gets specific about the machinery—why Metasploit is a strong signal and Exploit-DB is a weak one, why nobody hand-assigns weights, where the "23% more accurate" stat in v5 actually comes from—and closes with the gun-to-the-head threshold answer that surprises almost everyone who hears it: not 0.9, but 0.03. In our in-depth discussion, Jay shares: 00:03:19 — Jay Jacobs, Cyentia, and the Side Project That Became EPSS 00:06:53 — The 2–5% Number and What CVSS Actually Measures 00:13:11 — Why EPSS Had to Be Given Away 00:18:01 — Building the Model 00:24:07 — Grading the Model in Public 00:29:45 — EPSS v5 and Where "23% More Accurate" Comes From 00:35:27 — Who Funds It and Who's Using It 00:41:13 — AI-Written Exploits 00:46:37 — The Number for the Frustrated CISO

Ratings & Reviews

5
out of 5
2 Ratings

About

A cybersecurity podcast. Cyber conversations with more signal, less Noise. Noise2Signal is the antidote to the cybersecurity echo chamber: unfiltered conversations with the people who actually built the field — no buzzword bingo, no vendor pitches.