Skip to content
Artwork for Noise2Signal
BusinessTechnology

Noise2Signal

Mehul Revankar

A cybersecurity podcast. Cyber conversations with more signal, less Noise.

Noise2Signal is the antidote to the cybersecurity echo chamber: unfiltered conversations with the people who actually built the field — no buzzword bingo, no vendor pitches.

Play
  • 16 episodes
  • Avg 58 min
  • English
  • S2 · E4
    Tuesday · 35 min

    Ep 16. The Accidental Entreprenuer w/ Alan Shimel. CEO Techstrong Group

    Alan Shimel didn't plan on becoming cybersecurity media's kingmaker—he planned on being a lawyer. He passed the bar at 23, and the only thing that made him "tech savvy" in a New York law office was knowing WordPerfect better than anyone else in the building. But a home lab, a pair of 386 machines that needed to talk to each other, and a front-row seat to the birth of the web pulled him sideways into hosting, then into StillSecure as a founding executive going head-to-head with the people who would build Qualys and Tenable, and eventually into building the media empire behind DevOps.com, Security Boulevard, and TechStrong TV. In this episode, Alan—founder and CEO of TechStrong Group—tells Mehul the unfiltered version of that path: the $49.95-a-month hosting hustle that grew to 5,000 sites in 18 months, the dinner where Gene Kim first pitched him The Phoenix Project, the FeedBurner sale that accidentally handed him the Security Bloggers Network, and why he thinks the entire "open source vs. closed source AI" fight is really an argument about open weights. He also gets refreshingly blunt about Google's zero-click AI Overviews breaking the deal that funded the open web, and why the future of IT and journalism alike comes down to imagination—the one thing he doesn't think AI has.

    • Transcript
  • S2 · E3
    August 18 · 45 min

    Ep 15. The Don of Security Ratings Mafia w/ Aleksandr Yampolskiy

    Alexander Yampolsky didn't set out to invent a category—he just didn't want to get fired for someone else's mistake. As CISO at Gilt Groupe, he watched a fraud-prevention vendor hand over a gorgeous SOC 2 report and then discovered unencrypted credit card data belonging to other customers sitting in their systems. That moment became SecurityScorecard, the company that now scans every IP address on the planet multiple times a day and quietly underwrites a huge chunk of the cyber insurance market. In this episode, Alex—known around the industry as the Don of the security ratings mafia—walks through the unglamorous version of the origin story: the investors who told him security couldn't be measured, the MongoDB decision that haunted his engineers for eight years, the five hours of a stranger's divorce story it took to buy the .com. He also gets refreshingly blunt about why compliance isn't security, why rating pushback is often legitimate, and what happens to the entire discipline when the time-to-exploit window collapses from two years to seconds.

    • Transcript
  • S2 · E2
    August 11 · 56 min

    EP 14. Inside the Verizon DBIR w/ Alex Pinto

    Alex Pinto leads the team behind the Verizon Data Breach Investigations Report—the one publication the entire security industry stops and reads every single year. What almost nobody realizes is that the DBIR, now nineteen years old and built on data from over a hundred contributing partners, is written by exactly four people. In this episode, Alex pulls back the curtain on how the sausage actually gets made: the Verizon marketing team that fought tooth and nail to kill the very first edition, the Secret Service handshake that unlocked everyone else's data, and why the team flatly refuses to tell you which vendor supplied which number. He also walks us through the 2026 findings—vulnerability exploitation finally claiming the top spot after a four-year climb, a CISA KEV remediation rate that somehow went down, and shadow AI rocketing into the top three ways confidential data walks out of your building. Plus, the hunt for objective proof that attackers are using AI, why he thinks all of this will sound like business as usual by next year, and a genuinely excellent argument for why ransomware is the yoga pants of cybersecurity.

    • Transcript
  • S1 · E11
    August 11 · 48 min

    EP 11. Building Future of AI-Native Cyber Defense w/ Sasan Padidar

    Sasan is a veteran product builder with over 20 years of cybersecurity experience. In this episode, Sasan shares his journey from creating an early container security startup, navigating an acquisition by Tenable, and eventually building CrowdStrike's cloud security module into a $100M ARR business. We explore the early misconceptions surrounding Docker security, the architectural hurdles of moving legacy on-prem software to the cloud, and a harrowing tale of a $100K crypto-mining AWS bill. Sasan also details his recent pivot to the world of AI, explaining why human hype is often worse than AI hallucinations, how AI is fundamentally changing the speed of cyber attacks, and why defenders must rebuild their architectures to survive the next generation of threats.

    • Transcript
  • S2 · E1
    August 5 · 56 min

    EP 13. Vulnerability Research is Not Cooked w/ Thomas Dullien (Halvar Flake)

    Thomas Dullien—better known to the cybersecurity world as the legendary Halvar Flake—didn't just participate in the early cracking scene; he helped define it. As a computing mathematician and the mastermind behind BinDiff, Thomas revolutionized how we understand silent patches and reverse engineering. He eventually sold his pioneering company, Zynamics, to Google, but the journey was anything but smooth. In this episode, we get a no-holds-barred look at his origin story, why building a business around reverse engineering is a massive headache, and the excruciating reality of early tech M&As. Plus, Thomas delivers a sobering, provocative take on how agentic AI and infinite compute are about to rewrite the rules of vulnerability research—and why the human element isn't going anywhere anytime soon.

    • Transcript
  • S1 · E12
    July 1 · 1 hr 6 min

    EP 12. Building Companies, Culture, & Cyber Offense and Defense in the Age of AI w/ Ron Gula'

    Ron Gula is a cybersecurity pioneer, venture capitalist, and the visionary founder behind Tenable. Having bootstrapped his way to a $50 million Series A and scaled one of the industry's most recognizable brands, Ron has witnessed the highs and lows of company building. In this episode, we explore the authentic culture he established during Tenable's early days, the critical mistakes founders make when pitching venture capital, and the shifting landscape of building startups in the AI era. Ron details the strict rules of his famous "five-slide pitch deck," explains why AI wrappers are simply integrators rather than innovators, and warns that CISOs must take charge of AI operations before they are replaced by automated platforms. In our in-depth discussion, Ron shares: [00:04:21] Shaping Tenable's early culture with Cyndi Gula and Renaud Deraison. [00:08:10] Offering a junior employee a 4-day workweek during the 2008 crisis. [00:09:55] Talking a customer out of buying unneeded vulnerability scanners. [00:17:05] Creating "V-Ron," an unfiltered 3D avatar for controversial opinions. [00:22:44] Secondary sales that enrich employees versus traditional VC rounds. [00:24:51] Why sub-$1M ARR startups raising $30M rounds is a major red flag. [00:27:15] The strict "five-slide pitch deck" methodology to secure funding. [00:35:08] Pitching mistakes: leading with advisor names instead of solutions. [00:37:51] The danger of AI wrappers: becoming an integrator, not an innovator. [00:45:56] The impending platformization and consolidation of cybersecurity. [00:52:34] Predicting the replacement of CISOs by AI operations and MSSPs. [00:52:58] Why CISOs must aggressively lobby to run internal AI operations. [00:57:40] Why cyber hygiene fails against nation-states, requiring air gaps. [00:59:25] The economic realities of rising ransomware costs and falling payouts. [01:04:23] The future of AI-Native offense and Defense

    • Transcript
  • S1 · E10
    June 15 · 56 min

    EP 10. The Creation of Exposure Management Category w/ Jennifer Johnson

    JJ is an elite marketing visionary and category creator, shaping the narrative for cybersecurity giants like Tanium, Tenable, and CrowdStrike. In this episode, we pull back the curtain on the birth of the "Exposure Management" category at Tenable, exploring the strategic shift from legacy vulnerability management to holistic risk framing pre-IPO. JJ breaks down the "magic triangle" of category creation, the delicate dance of gaining executive and sales alignment, and the critical role industry analysts like Gartner play. We also dive into the future of marketing, the massive disruption of agentic AI, and how emerging technologies are spawning entirely new cybersecurity categories like AIDR. In our in-depth discussion, JJ shares: 00:02:57 - Earning a reputation as an elite CMO at Tanium, Tenable, and CrowdStrike. 00:04:05 - Identifying as a CMO first and a category creator second. 00:08:24 - Utilizing the "magic triangle" from Play Bigger for category design. 00:10:09 - Expanding Tenable's vision beyond the traditional vulnerability management market. 00:13:46 - Shifting the conversation from point-in-time compliance to continuous risk. 00:15:00 - The internal naming debate between "Cyber Exposure" and "Exposure Management". 00:16:29 - The tension between vendor innovation and analyst-defined categories. 00:22:40 - Unveiling Tenable's new identity with a dramatic, sensory presentation. 00:25:01 - Securing executive alignment by finding the correct problem narrative. 00:30:55 - Overcoming sales team friction when introducing a multi-year category vision. 00:34:10 - Validating the new exposure narrative with forward-leaning advisory customers. 00:35:29 - Driving M&A product strategy to cover the entire IT and OT attack surface. 00:40:43 - The milestone moment when Gartner officially adopted the Exposure Management category. 00:41:42 - The future convergence of threat and exposure management in the era of Frontier AI. 00:44:47 - Debating if Agentic AI represents a new category or just an existing feature. 00:45:22 - How AI expands attack surfaces and spawns new categories like AIDR. 00:48:33 - Why human judgment and the "human in the loop" remain strictly essential. 00:50:23 - Orchestrating cross-functional marketing workflows with AI agents. 00:55:01 - Embracing an AI-assisted interior design hobby outside of cybersecurity.

    • Transcript
  • S1 · E9
    June 7 · 54 min

    EP 9. Do AI or Be Replaced by AI w/ Craig Adams. AI-Native Future of Cyber Offense, Defense & PM

    Craig Adams is a seasoned cybersecurity product leader with over 20 years of experience building and scaling industry-defining tools. Having served as the Chief Product Officer at Rapid7 and Chief Product and Engineering Officer at Recorded Future, Craig has steered some of the most prominent teams in enterprise tech through massive evolutionary shifts. In this episode, we unpack how the age of AI has fundamentally rewritten the roles of product management, user experience, and software engineering. Craig challenges the "SaaS apocalypse" narrative, explains why AI-generated code will cause an exponential explosion of vulnerabilities, and argues why human information security teams will actually grow in size to handle the complex, agentic future of tech. In our in-depth discussion, Craig shares: 00:04:01 - Why the traditional waterfall requirements document is dead in the age of AI. 00:05:40 - How the role of the software engineer is transitioning to architectural oversight. 00:06:19 - The core strategy differences between running B2B and B2C product management. 00:07:28 - The merging lines between PM and UX design systems. 00:08:58 - Why the role of the prompt engineer has already gone out of fashion. 00:10:06 - Walking the floor at RSA and the problem with copycat cybersecurity marketing. 00:12:03 - The shift from SEO to AEO (AI Engine Optimization) for scraping agents. 00:13:12 - The rise of sandbox-driven trial loops and the death of human-led software demos. 00:14:46 - Buying enterprise AI subscriptions purely on self-serve product value. 00:16:13 - Facing the "Mythos" vulnerability hype and how AI disrupts raw discovery. 00:19:23 - Why putting 5x more findings into a discovery bucket is an unsustainable model. 00:21:52 - Reframing the cybersecurity dilemma as an implementation problem. 00:22:59 - How AI is binarily decreasing the time to exploitation for attackers. 00:25:00 - A religious-level conviction that the number of human defenders will grow, not shrink. 00:27:35 - Why entry-level information security roles are in the center of the AI bullseye. 00:29:48 - The new reality of writing functional exploits using simple natural language prompts. 00:32:31 - Debunking the idea that AI-generated code will plateau software exposures. 00:33:32 - Shifting defender terminology to focus on "toxic combinations" rather than simple patching. 00:35:13 - Redefining SaaS software: Either you embed AI or you get replaced by it. 00:36:06 - Navigating the inequality between well-funded banks and under-budgeted municipalities. 00:39:49 - Why security teams who block AI usage will ultimately hinder their enterprise. 00:40:14 - Moving past the chatbot era of 2023 into true automated agency. 00:41:57 - The dramatic leapfrog analogy: Treating the adoption of AI like switching from mail to email. 00:44:23 - Dismantling the platformization myth of "one security platform to rule them all." 00:45:47 - The thesis behind why the next trillion-dollar tech giant will be a services organization. 00:48:00 - Predicting a renaissance of software-like margins inside the IT services industry. 00:49:56 - Automating lower-value tier-one analyst tasks to focus on higher maturity journeys.

    • Transcript
  • S1 · E8
    June 1 · 1 hr 21 min

    EP 8. The Buyer's Seat w/ Aysha Khan. Inside the Mind of CISOs Buying in AI Era

    Aysha is a technology executive with over 25 years in cybersecurity, most recently serving as CISO and CIO at Treasure Data. Known for her "spiritual CISO" persona, she blends deep operational experience with a monk-like clarity — cutting through vendor noise with equal parts wisdom and candor. In this episode, we explore the frustrations behind her Buyer's Seat series, the chronic delivery problem plaguing the cybersecurity industry, and a no-holds-barred look at how buyers actually evaluate, adopt, and renew software. Aysha shares her structured vendor evaluation process, what "fantasy math" ROI really signals, and how AI is fundamentally reshaping how she leads her team.

    • Transcript
  • S1 · E7
    May 20 · 1 hr 42 min

    EP 7. The History Of Vulnerabilities w/ Brian Martin. From 1993 to Current Era.

    In this episode, we sit down with Brian Martin — 33-year vulnerability historian and longtime OSVDB maintainer — to trace the chasm between what CVE actually tracks and what's really out there. Brian explains why VulnCheck's KEV is 3.5x bigger than CISA's, why the real public vulnerability count is missing somewhere between 500K and several million entries, and how he personally mined 105,000 vulns out of changelogs and bug trackers. The conversation digs into the manufactured 2024 funding crisis, NVD's quiet abandonment of a 30,000-vuln backlog, why CVSS V4 is a "train wreck," and the LLM-driven vulnerability spike about to dwarf the fuzzer era. They close on the 1903 Marconi wireless telegraph hack — the first documented exploit-in-the-wild.

    • Transcript
  • S1 · E6
    May 13 · 1 hr 3 min

    EP 6. Meme King. Covering AI, Cybersecurity, Acquisitions & everything in between w/ Pramod Gosavi

    In this episode, we sit down with investor Pramod to break down the deals, valuations, and strategic plays reshaping cybersecurity and AI. Pramod unpacks Nikesh Arora's "sell-to-me-or-I-build-it" M&A playbook, the dirty economics behind AI darlings like Cursor and Claude Code, and the looming SaaSpocalypse pitting AI startups against legacy vendors for the same IT budget. The conversation digs into Nvidia's circular money flow with OpenAI, Anthropic, and CoreWeave, why this AI cycle is the inverse of dot-com, and a sharp take on why Cloudflare commands the highest multiple in security while Okta leaves money on the table.

    • Transcript
  • S1 · E5
    May 11 · 59 min

    EP 5. Past, Present & Future of CISA KEV w/ Patrick Garrity

    In this episode, Mehul sits down with vulnerability management influencer Patrick Garrity to unpack the rapidly shifting landscape of vulnerability exploitation. Patrick discusses how his unique data visualizations put CISA KEV on the map, but reveals the hidden limitations of the federal catalog today. He breaks down the recent geopolitical and funding crises paralyzing NIST’s NVD, highlighting how the private sector and projects like CISA's Vulnrichment are stepping up to fill the data void. The conversation also explores how MFA pushed threat actors toward network edge exploitation, the alarming reality of shrinking zero-day timelines, and why "exploitable by AI" might soon become the ultimate threat metric. Finally, they cover the looming impact of frontier AI models on mass bug discovery and how incoming European regulations will force companies to disclose active exploits within 24 hours. In this episode, Patrick shares: [00:01:48] How his unique data visualizations ultimately put CISA KEV on the map. [00:02:37] His journey from sales engineering at Duo to becoming a vulnerability data storyteller. [00:06:24] The early struggles of trying to contribute real-world exploit evidence to CISA KEV. [00:08:38] What the pre-CISA KEV era looked like, including scraping Twitter feeds for intel. [00:10:09] How SOC teams literally used a journalist's tweets as their primary exploitation feed. [00:11:48] Why the federal CISA KEV catalog only tracks ~1,500 exploits. [00:15:09] Why ENISA KEV's tiny catalog of 15 matters more than the label. [00:14:12] When VulnCheck’s CEO decided to give away their valuable commercial KEV data. [00:16:42] The death of Flash, IE, and Word macro exploits—and the rise of edge attacks. [00:18:25] An analysis of the Progress MOVEit attacks and the rise of "smash-and-grab" extortion. [00:23:24] Getting mocked for joining VM in 2022 because the industry thought it was "solved." [00:27:56] The funding crises that brought global CVE enrichment at NIST NVD to a halt. [00:34:05] The night the CVE program almost lost its funding entirely. [00:36:05] How 32K unenriched vulns were reclassified as "not scheduled" to clear their backlog. [00:41:40] The terrifying metric showing 26% of exploited vulns see action before a patch exists. [00:43:10] The rapid evolution of AI-generated bug reports from "slop" to legitimate. [00:48:02] Why "exploitable by AI" might replace CVSS and CISA KEV as the ultimate metric. [00:50:58] How Anthropic's Glasswing successfully found 300 real vulns in Firefox. [00:53:12] The possibility of attackers stealing proprietary source code specifically to feed into AI. [00:53:31] Why AI tools shipping without security in mind will become the next leakage problem. [00:54:38] War stories from the ProxyLogon exploits and the FBI's unprecedented interventions. [00:56:30] The time CrushFTP got mad at VulnCheck just for assigning a CVE ID to a vuln.

    • Transcript
  • S1 · E4
    April 30 · 54 min

    EP 4. Past, Present & Future of Risk Based Vulnerability Management with Ed Bellis

    Ed Bellis is the visionary who essentially created the Risk-Based Vulnerability Management (RBVM) category in 2010. From his days as CISO at Orbitz to founding Kenna Security in a market that didn't yet know it needed prioritization, Ed has consistently pushed the boundaries of cybersecurity. In this episode, Ed unpacks the grueling reality of convincing early investors and customers to put their vulnerability data in the cloud, the game-changing pivot that gave Kenna true product-market fit, and the candid truth behind what went wrong after the massive Cisco acquisition. He also dives into his new venture, Empirical Security, the role of AI in "eating the scanner," and why the industry needs to finally ditch the fear-mongering.

    • Transcript
  • S1 · E3
    April 30 · 48 min

    EP 3. The Face of New Media for Cybersecurity with Cole Grolmus, Founder Strategy Of Security

    Cole Grolmus is the ultimate "N of one" in cybersecurity media. After a decade at PwC and a failed startup, he hit reset, writing a 65,000-word reflection that birthed Strategy of Security. Today, he cuts through the industry noise with brutally honest, deeply researched strategy analysis. In this episode, Cole breaks down his viral cybersecurity ecosystem map, the dangerous reality of blitzscaling, and why the AI revolution won't wipe out heavyweights like CrowdStrike. We also get an inside look at how he completely reinvented his independent media empire using advanced AI agents.

    • Transcript
  • S1 · E2
    April 30 · 44 min

    EP 2. Past, Present and Future of Offensive Security w/ HD Moore

    HD Moore started the Metasploit framework project in 2003, forever changing the game on offensive security. Today, he serves as the CEO of runZero, mapping out global networks from behind the firewall. In this episode, we dive into the scrappy early days of internet security and dumpster diving for computer parts, why the AI revolution might make traditional vulnerability research and CVEs obsolete, and the brute-force reality of modern cybersecurity venture capital. We also explore how HD's deep technical roots helped him build runZero to $1M ARR as a solo operation, plus he shares the hilarious history of how the Blaster worm broke the internet using Metasploit's default port.

    • Transcript
  • S1 · E1
    April 30 · 1 hr 8 min

    EP 1. Bromure Secure Browser, Nessus Origins, Overbearer Proxy, Coding with AI, Fundraising in AI

    Renaud Deraison started the Nessus project in 1998 and co-founded Tenable, fundamentally changing how the world handles defensive cybersecurity. Today, he is leveraging AI to build and ship open-source security tools in a matter of weeks. In this episode, we dive into the early days of internet security and hardware scarcity , why the AI revolution might make traditional AppSec obsolete , and the exit pressures of the modern VC landscape. We also explore how deeply technical founders are gaining an "unfair advantage" by knowing exactly how to guide AI agents , plus Renaud shares the hilarious honeypot story that led to his new secure virtualized browser, Bromure.

    • Transcript
Showing 1–16 of 16 episodes