Resilient Cyber

Chris Hughes

Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.

  1. Aug 11

    Building a System of Truth for the CISO

    CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that. In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder behind Fortify and Respond Software. We dig into why the security leader has never had a system of truth the way the CFO has an ERP and the CRO has a CRM, and how an agentic layer on top of the existing tools can finally close that gap. Mike is measured about where AI gets to decide and where the human stays in the seat, and he shares what surprised him most from research with more than 80 senior practitioners and corporate directors. In this episode: - Why two exits later Mike came back to build a third company around the AI wave - The silos that left CISOs with an acronym soup of tools and no way to run the program - What a system of truth for the CISO actually means and how it layers on top of existing structured and unstructured data - Where agents do the heavy lifting on regulatory monitoring, vendor intelligence, and status reporting - Governing the guardrails, not the keystrokes, and why closing the loop still involves people - What corporate directors actually want to hear in the 15 to 20 minutes a CISO gets each quarter - The findings that stood out, including that 55% of boards have never defined the cyber risk they are willing to accept, and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk - Institutionalizing the tribal knowledge every security program runs on Chapters: 0:00 Intro 0:18 Mike's background and two prior exits 1:08 Why the AI wave pulled him back 2:21 Why the CISO has no system to run the program 4:09 Starting at the program level, not the SOC or AppSec 5:28 What a system of truth for the CISO means 8:19 Speaking the language of the business 9:09 Where AI does the heavy lifting on a typical Tuesday 11:57 Govern the guardrails, not the keystrokes 15:44 Bringing deputies into the conversation 16:46 What the research with senior practitioners found 20:37 Boards, risk tolerance, and the reporting gap 24:57 AI as a double-edged sword for security leaders 25:35 Joanna Burkey and institutionalizing tribal knowledge 27:31 A year from now for the security leader Guest links: Mike Armistead on LinkedIn Pulse Security on AI More Resilient Cyber: Substack: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders.

  2. Aug 5

    The Real Price Tag On Cyber Breaches

    Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations. For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we dig into what the data shows, where it stops, and how a security leader should actually use it. Alex Pinto runs the Data Breach Investigations Report team at Verizon Business and has been building the report for close to a decade. The Breach Impact Study is the team's first focused spin-off from the DBIR. In this episode: - How the Breach Impact Study came together and why the DBIR team finally got cyber insurance claims data - Why the study measures insurable loss as a floor, not a ceiling, of real economic impact - The case for reporting medians over averages, and why the team refuses to publish the average - Business interruption versus contingent business interruption, and why downtime moves the needle - Whether an $83,000 median breach impact sends executives the wrong message - The SMB paradox, where the smallest companies take the hardest proportional hit - What the claims data does and does not show about AI on offense and defense - Third-party risk, coverage sub-limits, and the single biggest takeaway for security leaders Chapters 0:00 Intro 0:24 Meet Alex Pinto and the DBIR team 2:51 Launching the Breach Impact Study 3:26 Getting cyber insurance claims data 7:32 Why insurable loss is a floor, not a ceiling 11:14 Medians over averages, and why the average is meaningless 15:13 Business interruption vs contingent business interruption 19:49 Does an $83K median send the wrong message? 22:44 The SMB paradox and the cybersecurity poverty line 26:05 Where AI shows up, offense vs defense 34:48 The CVE explosion and marketing hype 36:59 Third-party risk and coverage limits 41:34 Wrap-up Guest links Alex Pinto on LinkedIn: https://www.linkedin.com/in/alexcpsec/ Alex Pinto on X: https://x.com/alexcpsec Verizon DBIR and Breach Impact Study: https://www.verizon.com/business/resources/reports/dbir/ More from Resilient Cyber Substack: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders. #cyberrisk #databreach #cyberinsurance #ransomware #aisecurity #dbir

  3. Jul 30

    AI, Bug Bounties & the Vulnerability "Slopdemic"

    Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next. Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time. In this episode: Casey's path from building Bugcrowd to advising, investing, and policy workWhy more practitioners need to get involved in policy, and why law is just codeThe slopdemic vs. the vulnpocalypse, and what actually changed in submissionsAI lowering the bar for a broader, less predictable pool of threat actorsDaniel Stenberg, curl, and maintainers below the security poverty lineThe lightning rod vs. rockets distinction between VDPs and bug bountiesThe pentest market correction underway from AI pricing pressureCollapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.ioChapters: 0:00 Intro and Casey's background  2:56 Why practitioners belong in policy  6:22 The slopdemic vs. the vulnpocalypse  9:40 AI lowering the bar for threat actors  11:47 Open source, curl, and the security poverty line  15:37 VDP vs. bug bounty readiness  19:20 The pentest market correction  24:20 What breaks first in vulnerability management  27:20 Hack-back and non-cooperative defense  28:43 A near-term playbook for security leaders  31:40 CFAA, SRLDF, and disclose.io Connect with Casey:  LinkedIn: https://www.linkedin.com/in/caseyjohnellis Blog: https://cje.io disclose.io: https://disclose.io Bugcrowd: https://www.bugcrowd.com Resilient Cyber: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders.

  4. Jul 29

    AI's Cyber Boom

    Jon Sakoda of Decibel joins me to break down AI's impact on cybersecurity startups, venture funding, and why endpoint is the Super Bowl of cyber. Jon is the Founding Partner at Decibel, an early-stage firm backing technical founders in security and infrastructure. He started his career founding IMlogic, an IM security company acquired by Symantec, then spent over a decade at NEA working with companies like Cloudflare, MongoDB, and HackerOne before launching Decibel. We got into why he thinks AI is only magical if you have a magic power, why Decibel led a $100M seed into Ent, and where the firm is placing its next bets. In this episode: Why Decibel operates like the Navy SEALs next to the big platform fundsThe founder community model and finding the early believers among CISOsWhat separates the founders who finish now that AI lets everyone startEnt's $100M seed and the self-driving moment for endpoint securityTelling genuinely AI-native companies apart from AI washingAI eating venture capital and why cyber's best years are aheadOpen models, frontier labs, and why the cat is out of the bagThe agentic SOC, Dropzone AI, and driver assistance vs. self-drivingStartup consolidation cycles and being an N of oneHow buyers and job seekers should evaluate early-stage vendorsDecibel's next bets, from novel AI models to resilience and cyber insuranceChapters: 0:00 Intro  0:32 Jon's background and founding Decibel  2:25 Big platform funds vs. specialized firms  3:56 Founders helping founders and early believers  6:22 Scaling beyond the early adopters  7:40 Who finishes the marathon in the AI era  10:19 Founders from outside cyber  12:21 Ent's $100M seed and the endpoint bet  14:53 AI-native vs. AI washing  17:04 AI is eating venture capital  18:55 Open models vs. frontier labs  22:41 The agentic SOC and Dropzone AI  26:03 Consolidation and the startup cycle  29:22 How buyers should evaluate young vendors  31:43 Decibel's next bets and cyber resilience  34:11 Game Day at Black Hat Connect with Jon:  LinkedIn: https://www.linkedin.com/in/jonsakoda/ Decibel: https://www.decibel.vc Subscribe for more conversations with security practitioners and leaders, and find my writing at https://www.resilientcyber.io

  5. Jul 23

    Why AI Security Is Getting Rebuilt From Scratch

    In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading. Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, backing hardcore technology companies across AI infrastructure, cybersecurity, and physical AI. He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched. He is also early in companies like Keycard, Surf AI, and June. About a third of Boldstart's investments are in cyber, so Ed sees this market from the founder and investor side in a way most security conversations do not. We get into why the era of building raw intelligence is giving way to an era of controlling it, what that means for on-prem models and private evals, and why Ed thinks nearly everything in security is going to get rebuilt from scratch. In this episode: - Why a day-one partnership looks different now that anyone can vibe code an MVP - The Protect AI acquisition and what the first exit in AI security signaled to the market - Competing as an inception fund against mega-funds writing giant seed rounds - What founders should actually look for in a venture partner beyond the check - The shift from building intelligence to controlling it, including routing, post-training, and on-prem deployment - Why enterprise data, workflows, and private evals are becoming the crown jewels - Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation - Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins - The Surf AI thesis on automated security hygiene and tying every asset back to an owner - The real bottleneck slowing agent adoption in the enterprise Chapters: 0:00 Intro 0:35 Ed's background and inception investing 1:57 Day-one partnerships in the vibe-coding era 3:53 The Protect AI exit to Palo Alto 6:14 Competing as an inception fund against mega-funds 9:17 What founders should look for in a VC partner 11:48 From building intelligence to controlling it 15:52 Boldstart's domain-specific model portfolio 16:16 Private evals, context, and memory as crown jewels 17:18 Mythos, vulnerability chaining, and attack path reasoning 20:59 How much access should you give the model 22:07 On-prem context and the autonomous workforce 24:49 Agentic identity and Keycard 28:11 Building brand and community with Insecure Agents 31:30 The Surf AI thesis and automated security hygiene 34:13 The real bottleneck to agent adoption 37:09 The easy button, Palantir, and a multi-model world 38:24 Two types of people in this new era Connect with Ed: LinkedIn: https://www.linkedin.com/in/edsim/ Boldstart Ventures: https://boldstart.vc Ed's newsletter, What's Hot in Enterprise IT/VC: https://www.whatshotit.vc More from Resilient Cyber: Substack: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders. #aisecurity #agenticai #cybersecurity #venturecapital #appsec

  6. Jul 20

    Resilient Cyber w/ Joshua Saxe - Why Restricting AI Makes Us Less Secure

    Does restricting frontier AI in the name of safety actually make us less secure? Joshua Saxe joins me to make the case that it does, and that AI cybersecurity will be won through defender adoption, not restriction. Josh has spent 15 years at the intersection of AI and security. He built and ran the machine learning program at Sophos, then led security for Llama at Meta, covering security post training, evals, agent guardrails, and prompt injection prevention. He recently left to co-found a startup reimagining vulnerability and exposure management agentically. He also writes one of the most cited blogs on AI and cyber policy. In this episode: - Why restricting frontier model access harms defenders more than attackers - How monitored closed models put threat actors at a structural disadvantage - The jagged frontier, and why attackers don't need frontier models for most of their tradecraft - The national security and supply chain risks of pushing the world onto Chinese open weights models - Why exploits don't cause cyberattacks, and which attacker constituencies AI actually unblocks - The dual use ceiling on guardrails and classifiers - Where defenders should be adopting AI right now, from access management to SOC automation - Using agents to burn down the mountain of security technical debt Chapters: 0:00 Intro 0:42 Josh's background, from blackhat teen to Llama security lead 3:07 The case for diffusion over restriction 6:14 Why restriction hurts defenders more than attackers 10:19 The jagged frontier and what attackers actually use models for 12:49 National security and the supply chain risk of Chinese open weights 16:08 Exploits don't cause cyberattacks 20:20 Where defenders should adopt AI right now 24:20 Guardrails, classifiers, and the dual use problem 27:34 Reimagining vulnerability management with agents 32:17 The structural advantage defenders hold 35:15 Policy wishes and the attacker's Claude Code moment Follow Josh: LinkedIn: https://www.linkedin.com/in/joshua-saxe-01845a1 Substack: https://joshuasaxe181906.substack.com Follow Resilient Cyber: Substack: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders. #aisecurity #cybersecurity #vulnerabilitymanagement #aipolicy #opensourceai

  7. Jul 16

    Cyber Valuations, Moats & the Road to Black Hat

    Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat. Sid is a Partner at Foundation Capital, where he invests at the seed and Series A stage with a focus on cybersecurity and IT infrastructure. This is our annual pre-Black Hat check-in, and a lot has moved since last year, from massive M&A to record-setting rounds in categories like the AI SOC. In this episode: - What has actually changed a year into the AI wave, and what hasn't - Services-as-software, the $4.6 trillion market thesis, and automating cyber workflows across the SOC, IR, pen testing, and threat intel - What AI means for cybersecurity jobs and how practitioners should adapt - Consolidation vs. best-of-breed after Palo Alto's $25B CyberArk deal and Alphabet's $32B Wiz acquisition - AI SOC valuations, including Seven AI's record Series A and Torq crossing a $1B valuation - The double-edged sword of big raises and why founders should be cautious about the valuations they accept - Why you can't simply spend your way to growth in cybersecurity - Moats and defensibility when frontier labs can push into your category - The Black Hat Innovator Investor Summit and the Startup Spotlight competition Chapters: 0:00 Intro 0:52 What's changed a year into the AI wave 2:42 Services-as-software and the AI SOC 9:38 AI adoption and forward deployed engineers 10:57 M&A, platformization, and best-of-breed 14:17 IT and security convergence, plus AI SOC valuations 18:48 Seed-stage risk calculus vs. later-stage investors 21:43 The double-edged sword of big raises 26:20 Why you can't spend your way to growth 29:05 Moats and defensibility in the frontier-lab era 32:25 Deal flow, pricing, and staying disciplined 37:06 Black Hat Innovator Investor Summit 40:17 Startup Spotlight competition 43:28 Wrap-up Black Hat is offering listeners $500 off registration with code USA500Resilient. Connect with Sid: LinkedIn: https://www.linkedin.com/in/siddhanttrivedi/ Foundation Capital: https://foundationcapital.com Resilient Cyber: https://www.resilientcyber.io Subscribe for more conversations with security practitioners, founders, and leaders.

4.8
out of 5
17 Ratings

About

Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.

You Might Also Like