Episodes

  • The Real Price Tag On Cyber Breaches
    Aug 5 2026

    Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations.

    For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we dig into what the data shows, where it stops, and how a security leader should actually use it.

    Alex Pinto runs the Data Breach Investigations Report team at Verizon Business and has been building the report for close to a decade. The Breach Impact Study is the team's first focused spin-off from the DBIR.

    In this episode:
    - How the Breach Impact Study came together and why the DBIR team finally got cyber insurance claims data
    - Why the study measures insurable loss as a floor, not a ceiling, of real economic impact
    - The case for reporting medians over averages, and why the team refuses to publish the average
    - Business interruption versus contingent business interruption, and why downtime moves the needle
    - Whether an $83,000 median breach impact sends executives the wrong message
    - The SMB paradox, where the smallest companies take the hardest proportional hit
    - What the claims data does and does not show about AI on offense and defense
    - Third-party risk, coverage sub-limits, and the single biggest takeaway for security leaders

    Chapters
    0:00 Intro
    0:24 Meet Alex Pinto and the DBIR team
    2:51 Launching the Breach Impact Study
    3:26 Getting cyber insurance claims data
    7:32 Why insurable loss is a floor, not a ceiling
    11:14 Medians over averages, and why the average is meaningless
    15:13 Business interruption vs contingent business interruption
    19:49 Does an $83K median send the wrong message?
    22:44 The SMB paradox and the cybersecurity poverty line
    26:05 Where AI shows up, offense vs defense
    34:48 The CVE explosion and marketing hype
    36:59 Third-party risk and coverage limits
    41:34 Wrap-up

    Guest links
    Alex Pinto on LinkedIn: https://www.linkedin.com/in/alexcpsec/
    Alex Pinto on X: https://x.com/alexcpsec
    Verizon DBIR and Breach Impact Study: https://www.verizon.com/business/resources/reports/dbir/

    More from Resilient Cyber
    Substack: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners and leaders.

    #cyberrisk #databreach #cyberinsurance #ransomware #aisecurity #dbir

    Show more Show less
    42 mins
  • Cyber Investing in the AI Exploit Era
    Aug 1 2026

    What happens to security investing when vulnerability discovery becomes continuous and exploitation windows shrink from weeks to hours? I sit down with Chenxi Wang of Rain Capital to dig into it.

    Chenxi is the Founder and Managing General Partner at Rain Capital, a venture fund focused on early-stage cybersecurity companies. She's been a Carnegie Mellon professor, a Forrester VP, and a strategy leader at Intel Security and Twistlock, and her portfolio includes companies like Claroty, ProjectDiscovery, Ox Security, runZero, and Straiker. She closes out my July run of conversations with security investors.

    In this episode:

    • The AI Exploit Age and why vulnerability discovery is becoming continuous
    • Guardian Agents and the case that it takes an AI to govern an AI
    • Separating AI agent identity from traditional machine identity
    • The signals that predict enterprise adoption for early-stage security startups
    • The barbell funding market and the squeeze on Series B and C
    • What security leaders should do differently over the next twelve months

    Connect with Chenxi:
    LinkedIn: https://www.linkedin.com/in/chenxiwang88/
    Rain Capital: https://raincap.vc/
    Rain Capital Insights: https://raincapital.substack.com

    Subscribe to Resilient Cyber for more conversations with security practitioners and leaders: https://www.resilientcyber.io

    Show more Show less
    33 mins
  • AI, Bug Bounties & the Vulnerability "Slopdemic"
    Jul 30 2026

    Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.

    Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.

    In this episode:

    • Casey's path from building Bugcrowd to advising, investing, and policy work
    • Why more practitioners need to get involved in policy, and why law is just code
    • The slopdemic vs. the vulnpocalypse, and what actually changed in submissions
    • AI lowering the bar for a broader, less predictable pool of threat actors
    • Daniel Stenberg, curl, and maintainers below the security poverty line
    • The lightning rod vs. rockets distinction between VDPs and bug bounties
    • The pentest market correction underway from AI pricing pressure
    • Collapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.io

    Chapters:

    0:00 Intro and Casey's background
    2:56 Why practitioners belong in policy
    6:22 The slopdemic vs. the vulnpocalypse
    9:40 AI lowering the bar for threat actors
    11:47 Open source, curl, and the security poverty line
    15:37 VDP vs. bug bounty readiness
    19:20 The pentest market correction
    24:20 What breaks first in vulnerability management
    27:20 Hack-back and non-cooperative defense
    28:43 A near-term playbook for security leaders
    31:40 CFAA, SRLDF, and disclose.io

    Connect with Casey:
    LinkedIn: https://www.linkedin.com/in/caseyjohnellis
    Blog: https://cje.io
    disclose.io: https://disclose.io
    Bugcrowd: https://www.bugcrowd.com

    Resilient Cyber: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners and leaders.

    Show more Show less
    34 mins
  • AI's Cyber Boom
    Jul 29 2026

    Jon Sakoda of Decibel joins me to break down AI's impact on cybersecurity startups, venture funding, and why endpoint is the Super Bowl of cyber.

    Jon is the Founding Partner at Decibel, an early-stage firm backing technical founders in security and infrastructure. He started his career founding IMlogic, an IM security company acquired by Symantec, then spent over a decade at NEA working with companies like Cloudflare, MongoDB, and HackerOne before launching Decibel. We got into why he thinks AI is only magical if you have a magic power, why Decibel led a $100M seed into Ent, and where the firm is placing its next bets.

    In this episode:

    • Why Decibel operates like the Navy SEALs next to the big platform funds
    • The founder community model and finding the early believers among CISOs
    • What separates the founders who finish now that AI lets everyone start
    • Ent's $100M seed and the self-driving moment for endpoint security
    • Telling genuinely AI-native companies apart from AI washing
    • AI eating venture capital and why cyber's best years are ahead
    • Open models, frontier labs, and why the cat is out of the bag
    • The agentic SOC, Dropzone AI, and driver assistance vs. self-driving
    • Startup consolidation cycles and being an N of one
    • How buyers and job seekers should evaluate early-stage vendors
    • Decibel's next bets, from novel AI models to resilience and cyber insurance

    Chapters:

    0:00 Intro
    0:32 Jon's background and founding Decibel
    2:25 Big platform funds vs. specialized firms
    3:56 Founders helping founders and early believers
    6:22 Scaling beyond the early adopters
    7:40 Who finishes the marathon in the AI era
    10:19 Founders from outside cyber
    12:21 Ent's $100M seed and the endpoint bet
    14:53 AI-native vs. AI washing
    17:04 AI is eating venture capital
    18:55 Open models vs. frontier labs
    22:41 The agentic SOC and Dropzone AI
    26:03 Consolidation and the startup cycle
    29:22 How buyers should evaluate young vendors
    31:43 Decibel's next bets and cyber resilience
    34:11 Game Day at Black Hat

    Connect with Jon:
    LinkedIn: https://www.linkedin.com/in/jonsakoda/
    Decibel: https://www.decibel.vc

    Subscribe for more conversations with security practitioners and leaders, and find my writing at https://www.resilientcyber.io

    Show more Show less
    35 mins
  • Why AI Security Is Getting Rebuilt From Scratch
    Jul 23 2026

    In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading.

    Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, backing hardcore technology companies across AI infrastructure, cybersecurity, and physical AI. He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched. He is also early in companies like Keycard, Surf AI, and June. About a third of Boldstart's investments are in cyber, so Ed sees this market from the founder and investor side in a way most security conversations do not.

    We get into why the era of building raw intelligence is giving way to an era of controlling it, what that means for on-prem models and private evals, and why Ed thinks nearly everything in security is going to get rebuilt from scratch.

    In this episode:

    - Why a day-one partnership looks different now that anyone can vibe code an MVP
    - The Protect AI acquisition and what the first exit in AI security signaled to the market
    - Competing as an inception fund against mega-funds writing giant seed rounds
    - What founders should actually look for in a venture partner beyond the check
    - The shift from building intelligence to controlling it, including routing, post-training, and on-prem deployment
    - Why enterprise data, workflows, and private evals are becoming the crown jewels
    - Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation
    - Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins
    - The Surf AI thesis on automated security hygiene and tying every asset back to an owner
    - The real bottleneck slowing agent adoption in the enterprise

    Chapters:

    0:00 Intro
    0:35 Ed's background and inception investing
    1:57 Day-one partnerships in the vibe-coding era
    3:53 The Protect AI exit to Palo Alto
    6:14 Competing as an inception fund against mega-funds
    9:17 What founders should look for in a VC partner
    11:48 From building intelligence to controlling it
    15:52 Boldstart's domain-specific model portfolio
    16:16 Private evals, context, and memory as crown jewels
    17:18 Mythos, vulnerability chaining, and attack path reasoning
    20:59 How much access should you give the model
    22:07 On-prem context and the autonomous workforce
    24:49 Agentic identity and Keycard
    28:11 Building brand and community with Insecure Agents
    31:30 The Surf AI thesis and automated security hygiene
    34:13 The real bottleneck to agent adoption
    37:09 The easy button, Palantir, and a multi-model world
    38:24 Two types of people in this new era

    Connect with Ed:
    LinkedIn: https://www.linkedin.com/in/edsim/
    Boldstart Ventures: https://boldstart.vc
    Ed's newsletter, What's Hot in Enterprise IT/VC: https://www.whatshotit.vc

    More from Resilient Cyber:
    Substack: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners and leaders.

    #aisecurity #agenticai #cybersecurity #venturecapital #appsec

    Show more Show less
    40 mins
  • Resilient Cyber w/ Joshua Saxe - Why Restricting AI Makes Us Less Secure
    Jul 20 2026

    Does restricting frontier AI in the name of safety actually make us less secure? Joshua Saxe joins me to make the case that it does, and that AI cybersecurity will be won through defender adoption, not restriction.

    Josh has spent 15 years at the intersection of AI and security. He built and ran the machine learning program at Sophos, then led security for Llama at Meta, covering security post training, evals, agent guardrails, and prompt injection prevention. He recently left to co-found a startup reimagining vulnerability and exposure management agentically. He also writes one of the most cited blogs on AI and cyber policy.

    In this episode:
    - Why restricting frontier model access harms defenders more than attackers
    - How monitored closed models put threat actors at a structural disadvantage
    - The jagged frontier, and why attackers don't need frontier models for most of their tradecraft
    - The national security and supply chain risks of pushing the world onto Chinese open weights models
    - Why exploits don't cause cyberattacks, and which attacker constituencies AI actually unblocks
    - The dual use ceiling on guardrails and classifiers
    - Where defenders should be adopting AI right now, from access management to SOC automation
    - Using agents to burn down the mountain of security technical debt

    Chapters:
    0:00 Intro
    0:42 Josh's background, from blackhat teen to Llama security lead
    3:07 The case for diffusion over restriction
    6:14 Why restriction hurts defenders more than attackers
    10:19 The jagged frontier and what attackers actually use models for
    12:49 National security and the supply chain risk of Chinese open weights
    16:08 Exploits don't cause cyberattacks
    20:20 Where defenders should adopt AI right now
    24:20 Guardrails, classifiers, and the dual use problem
    27:34 Reimagining vulnerability management with agents
    32:17 The structural advantage defenders hold
    35:15 Policy wishes and the attacker's Claude Code moment

    Follow Josh:
    LinkedIn: https://www.linkedin.com/in/joshua-saxe-01845a1
    Substack: https://joshuasaxe181906.substack.com

    Follow Resilient Cyber:
    Substack: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners and leaders.

    #aisecurity #cybersecurity #vulnerabilitymanagement #aipolicy #opensourceai

    Show more Show less
    37 mins
  • Cyber Valuations, Moats & the Road to Black Hat
    Jul 16 2026

    Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat.

    Sid is a Partner at Foundation Capital, where he invests at the seed and Series A stage with a focus on cybersecurity and IT infrastructure. This is our annual pre-Black Hat check-in, and a lot has moved since last year, from massive M&A to record-setting rounds in categories like the AI SOC.

    In this episode:
    - What has actually changed a year into the AI wave, and what hasn't
    - Services-as-software, the $4.6 trillion market thesis, and automating cyber workflows across the SOC, IR, pen testing, and threat intel
    - What AI means for cybersecurity jobs and how practitioners should adapt
    - Consolidation vs. best-of-breed after Palo Alto's $25B CyberArk deal and Alphabet's $32B Wiz acquisition
    - AI SOC valuations, including Seven AI's record Series A and Torq crossing a $1B valuation
    - The double-edged sword of big raises and why founders should be cautious about the valuations they accept
    - Why you can't simply spend your way to growth in cybersecurity
    - Moats and defensibility when frontier labs can push into your category
    - The Black Hat Innovator Investor Summit and the Startup Spotlight competition

    Chapters:
    0:00 Intro
    0:52 What's changed a year into the AI wave
    2:42 Services-as-software and the AI SOC
    9:38 AI adoption and forward deployed engineers
    10:57 M&A, platformization, and best-of-breed
    14:17 IT and security convergence, plus AI SOC valuations
    18:48 Seed-stage risk calculus vs. later-stage investors
    21:43 The double-edged sword of big raises
    26:20 Why you can't spend your way to growth
    29:05 Moats and defensibility in the frontier-lab era
    32:25 Deal flow, pricing, and staying disciplined
    37:06 Black Hat Innovator Investor Summit
    40:17 Startup Spotlight competition
    43:28 Wrap-up

    Black Hat is offering listeners $500 off registration with code USA500Resilient.

    Connect with Sid:
    LinkedIn: https://www.linkedin.com/in/siddhanttrivedi/
    Foundation Capital: https://foundationcapital.com

    Resilient Cyber: https://www.resilientcyber.io
    Subscribe for more conversations with security practitioners, founders, and leaders.

    Show more Show less
    42 mins
  • Building an AI AppSec Engineer
    Jul 11 2026

    JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.

    Description

    AppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once.

    We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.

    Key takeaways

    • Gecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.
    • The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.
    • Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.
    • Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.
    • Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.
    • Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.
    • MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.
    • Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.
    • Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.
    • The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.

    Chapters

    00:00 Meet JJ and Ryan
    02:46 Why Gecko is an AI security engineer, not another scanner
    05:07 The trend of agentic and headless security tools
    05:53 Why business logic breaks traditional SAST
    06:27 The no-auth endpoint example and context outside the code
    09:06 Attackers think in graphs, defenders think in lists
    11:02 Commoditized exploit dev and the internet as one bug bounty
    13:55 Shift left and why MTTR is a broken metric
    15:07 Eliminating entire classes of vulnerabilities
    15:51 Recurrence rate and avoiding risky refactors
    18:22 The Cal.com case study and open source going closed
    20:48 Consolidation and the shiny object problem in security
    22:40 Where AI-driven AppSec lands in two years
    27:12 What it takes to trust an AI security engineer
    28:57 Where to find Gecko and the Black Hat talk

    Show more Show less
    31 mins