Latest / Noise2Signal / EP 12. Building Companies, Culture, & Cyber Offense and Defense in the Age of AI w/ Ron Gula'
Transcript
- speaker-0: Arun, it is such an honor to have you on Noise to Signal interview series. But one thing that rarely gets talked about is the culture that you created in the early days of Hannibal. I want to start the interview there. speaker-1: Right. I was surrounded by great people. So my wife, Cindy Goula, Jack Hufford, Renaud Darrison, they all brought a lot of different perspectives about how to take care of people. The CEO's job is to remove barriers for their employees, whether they need a a tool, they a policy change. speaker-0: And one person that shows up extensively in your interview series is V-Ron. And V-Ron is the virtual Ron. I'm curious if V-Ron is the Larry David version of Creel Ron from Curb Your Enthusiasm. speaker-1: I wanted to do sort of a Joe Rogan podcast. I really can't say that I have a founder who did a really bad job on a panel. And here's how we should all listen to it. So I found out I can do animation with characters. You know, the Pope just came out with an AI ethics thing. I read, I read the first half of it. I'm like, this is great. Go write a script on this. speaker-0: when Cannibal did its first series A. It was a 50 million series A. speaker-1: And when we raised those rounds, the fifty million dollar round, the three hundred million dollar round, not only were they record setting at the time, but they were direct secondary sales. And what that meant is that money went to the employees. With AI, what I'm telling people, whatever you do is almost irrelevant because you can make it with AI. So it's more important to engage your customer. speaker-0: your best or most prominent videos is the 5 slide fish tank. speaker-1: We did it out of a little bit out of frustration because we would get pitches from companies and we couldn't tell if it was a nonprofit or a commercial company, right? You know, you might be building a great product, but you're dependent upon that AI. Who what's who's got the real innovation there? Who's got the intellectual property? speaker-0: Do you think the AI transformation is similar compared to the cloud? How do startups build modes in the age of AI? What is the future of jobs with AI? speaker-1: What I what I'm saying is if you're a CISO, you should be fighting to run any AI initiative you have in your company. If you're not lobbying for that role, you're gonna be out of a job. speaker-0: Let's talk about the future of cyber offense and cyber defense. speaker-1: And you know, what that means in the age of AI, I think it means a couple of things. So what do you do? speaker-0: What's the next big video dropping from V-Ron? Ladies and gentlemen, please welcome Ron Gula, co-founder of Tenable and CEO at Gula Tech Adventures. We are live. Ron, is such an honor to have you on Noise to Signal interview series. You have been a founder, you have been an investor, you have been a board member, you have been a philanthropist, you have been a mentor and a coach for hundreds of startups. And you talk extensively about your ⁓ early days at Tenable. As I was preparing for this interview, I've been listening to a lot of your interviews. And you talk extensively about your early days and how you created Tenable, the journey of Tenable, and so on and so forth. But one thing that rarely gets talked about is the culture that you created in the early days of Tenable. And as an employee, I experienced it. at Tenable. And so I want to start the interview there. ⁓ This was your second startup, I'm correct. And I'm curious if the early culture of Tenable, was it organic or was it intentional the way you did it? Because there are two anecdotes I want to share from my perspective, but I want to get started with the way you created Tenable in the early days, the way we experienced it. ⁓ What was your thinking behind the culture that he created at Tenenbaum. speaker-1: Well, hey, it look, it's a pleasure to be on the ⁓ Single Sig noise to Signal podcast. Very proud of what you've done, you know, after after Tenable as well. I wish you a whole lot of luck with your with your new startup. But but look, the culture of Tenable, you know, we we I got lucky, right? I was surrounded by great people. So my wife, Cindy Gula, Jack Hufford, Renault Darrison, they all brought a lot of different perspectives about How to take care of people, how to have a culture, how to, how to grow things. But I gotta tell you, I mean, I I was in the Air Force, I got to experience leadership and command from a lot of different things. And I kind of said, I don't really like that. I kind of like this. I don't really like that. I kind of like this. And then, you know, I got to go to the NSA again see different leadership styles that some things I liked and I didn't like. And as we went through through through through the career, You know, Cindy and I had the benefit of starting a smaller company, Network Security Wizards, that made the Dragon IDS. And that was over a pizza shop, you know, and we eventually sold that. So a lot of this, how do you take care of people when the products, you know, selling and bringing bringing stuff in? We were very, very lucky that we always made products that people wanted. And they say, you know, you can't products don't sell themselves, but when you're making money from customers, you can put the customers on a pedestal. And basically enable your employees to support the customer and there's a big trust factor there. So, you know, today in 2026, you know, some of the things we were doing in the early 2000s, I think a lot of companies do, taking people to the movies, you know, during work hours, for example. ⁓ you know, doing ⁓ an all hands meeting with everybody. And, you know, today with so many remote people after COVID, it's tough. But you mentioned a couple of things, you know, Cindy and I we would get the donuts and the visibility of seeing us carry that stuff in. I think people say, you know, leader servant, you know, all that kind of stuff, but we really tried to just kind speaker-0: You live, you both live that philosophy. And I think the thing I want to say, you and Cindy were a great combination. And I say this with all the love because you were much more, Cindy was very strict. So I don't know if this like a bad cop, good cop kind of thing, where Cindy, Cindy was the most warm motherly figure that you could have in the office, but she would also be very strict. She would always be strict and you would always be very... open your office door was always open. could always walk in. Hey, Ron, just had a great idea. It was a great combination. And there are two things that I want to share. as you said, we would have this breakfast, Friday breakfast. We would have Thursday lunches. Everyone was in the office room in the cafeteria having lunch and we would share stories and whatnot. But I want to share like two stories from my days at Tenable and how I experienced it as an employee. And this was like, This was the worst time from an economic point of view. was 2008. The mortgage crisis was in full bloom and all the companies were fighting people left and right. I was still very new to the company. And my wife had gotten residency in New York. So I was essentially traveling back and forth. Friday evenings I would drive to New York and then Monday mornings I would come back I would drive down and obviously, know, some days I would get late for the early first Monday morning meetings. would like, you know, my eyes would be red, bags under my eyes. And, ⁓ And there was a sense of fear that, I don't want to tell this because people might perceive this. Hey, maybe he's going to New York. So I didn't tell this to anybody, but the word got out and you came to know about it. You came to know about it, that Mule has been traveling up and down every weekend. He's been doing all these things. And then one fine day I get a tap on my desk from you and I said, Friday, you get a tap. Hey, I just listened. I just heard that you're been traveling up and down. And I'm like, my heart is bit throbbing. What the hell? It's a Friday. What's going to happen? And you come and tell me, hi, do you want to work four days a week? Just work an hour, ⁓ two hours every day more and just take Friday off. And that was, I was just blown away by it because here's the CEO, comes to, I was a very junior engineer and comes to me, hey, I just heard about something that's happening. I was like, you know, it was very... impactful in that moment, in that crisis. Because if it was a normal time, no one would have cared. But this is like everyone was laying off people, but here is a CEO, like, my employees are struggling. Let me see if I can do something. And so I didn't take you up on the offer, but it was very impactful. so this is like for a leader taking care of the employee. The second aspect I want to share is, this is before this incident. but he would tag me along for these dinners with prospects, right? You know, I was single. was not doing anything in the unit. You would come in, hey, what you doing for dinner tonight? I'm like, nothing. And he would take me to these prospect dinners. And this was the time when we were selling $1200 Nessus feeds. We were selling $1200 Nessus feeds. That was my majority of our business. And ⁓ there was this prospect who was convinced he has to buy passive vulnerability scanner. And I don't know why, and it was probably a 10, $15,000 deal. Not a big deal, but maybe 10,000, that's subscription. So this is significant enough for us to warrant attention. And the guy was convinced that he needs to buy a PBS. And you realized for whatever reason that he doesn't need PBS. think whatever he had is good enough. He doesn't need to buy PBS. And the guy kept, during the dinner, the guy kept convincing you, hey, I need to buy this. And you're like, no, no, no, you don't need to buy it. And I, as an employee, was wondering, should I just jump in? and say, hey, we'll take the deal. Let's have dinner and then go. But the point I want to make is you also didn't, like one is obviously took care of the employees and the culture, but then you're also very, you're not trying to sell things customers didn't need. So you're also very customer focused in the sense that you are not trying to get more money. If there was a genuine need, you would sell everything and anything they would want. like both these incidents were very, You spoke a lot about your character and the company that you're building. I'm curious if you have any thoughts on that. speaker-1: Yeah, look, I appreciate bringing up both of those stories. And you look, I'm just gonna say, look, I was I was lucky, right? I was surrounded by really good people. We had enough revenue from customers that we didn't have the stress of having to fundraise and you know, we're still managed cash flow and stuff like that. But basically, you know, when you talk about giving you a day off, ⁓ or working fours, you know, that kind of thing. In the early two thousand, that was like progressive stuff that's very modern right now, especially after COVID. So things have really, really changed. But it the CEO's job is to remove barriers for their employees, whether they need a a tool, they a policy change, you know, something like that. And it's so hard. I mean, I think back in the day we were two hundred people, you know, which you could get everybody into one room at that point, but as soon as we got speaker-0: We to a movie theater for an all hands meeting. don't know if you remember that. We fit, tried to fit in, we booked the whole thing and then everyone was in there. speaker-1: And we really, you know, we really tried. So for example, when we went on these sales calls, you know, typically you go with a salesperson. If you're gonna bring the CEO in, there's probably a salesperson who set that up. And I always had a policy that's most of our research team, the people who wrote the vulnerability plugins and stuff like that, they were very distributed. So Renault ⁓ was always super concerned about ⁓ you know, how do you get culture with these guys? How do you get them together? So we did some you know, all hands with those kind of things. But I always made a point if I was doing a sales call in St. Louis, who from Tenable was there? Is it somebody in support, somebody in and Brigham to meet a customer? Right. So that was very, very important to me. And on the other hand, you know, you talk about selling stuff to customers. And of course, we invented so many things at Tenable, right? If you look at the career of just having to span from scanning a network all the way to auditing SaaS and cloud apps. And you know, of course, Tenable's continue that with AI auditing now and what whatnot. But every year there was a new technology. So the question is, what do the customers actually need? And I felt like Willy Wonka, like we were coming up with so many things that were ahead of that curve. ⁓ yeah. And I think you were right saying, look, the customer probably needs more coverage. ⁓ we had a major customer that didn't buy and so you you mentioned the passive vulnerability scanner. So imagine for people who don't know this, a sniffer, like a network intrusion detection system that gives you vulnerabilities. It's real time. No impact to your network, that sort of thing. And it can that can be a political problem because if your job is to scan for PCI violations or federal regulations and a sniffer can find it in real time, boy, that's that could be a big problem. That might have been the reason I was holding back a little bit on this, on this guy. But yeah, it's great to have things that people want and try to sell that, but the customer comes first. That's why the whole thing is is we had such a good time with with the customers. speaker-0: I never experienced any turbulence at Tenable in the early days. Was it always like that or was it always smooth sailing or were there scenarios where Tenable would not make speaker-1: So like like like now Gulatech Adventures, we're involved in almost 50 companies more because we're also involved with funds who invest in companies and we're kind of entangled with those things. So we we're we we can easily say we touch a hundred companies. So we've seen amazing success with poor CEOs, we've seen or founders, right? We've seen great founders that we think are great have poor success. So that there's really no way to predict those kind of things. But for Tenable in particular, you know, we had great success and You know, I don't think I ever got angry and yelled at anybody. We had to terminate people who didn't, you know, perform and w I I always felt we were slow to kind of make those changes in hindsight. ⁓ but it was, you know, I was pretty happy with the culture and and and and doing things. And look for we still live in Columbia, close to the Tenable Headquarters. So we'll run into people who are are there and we hear about the culture and the effect and you know, I'm at Uran, God rest his soul, you know, is doing doing a good job of mate maintaining that. Steve Vince's doing a good job. He was there, you know, seeing those kind of things. So so the the the the the point is is it's kinda hard to put your finger on what culture really is, but man, we we we got lucky with hiring good people. speaker-0: Awesome. And Ron, as I was preparing for this interview, I obviously listened to a lot of your interviews. And one person that shows up extensively in your interview series is Vron. And Vron is the virtual Ron. And obviously you are a very prominent public figure in cybersecurity. You have a lot of thoughts you want to share, but you cannot share because you have a public profile. I'm curious if Vron is the Larry David version of real rod from Kormir enthusiasm because V-RON is unfiltered. So I'm curious, what is the thinking behind V-RON? ⁓ And ⁓ yeah, I will just start there. speaker-1: So, you know, during COVID, I wanted to do sort of a Joe Rogan podcast with ⁓ you know, sit people around the table, in person, microphones, and and we did a lot of those. I think I did maybe, maybe 50 of those interviews. And I got some fairly senior cyber people from, you know, DHS on the show, Cyber Command, and it's and it's it's interesting. But, you know, what happened is I I'm gonna say I got briefed on The typhoons before they were kind of public. This was really just China hacking into routers. And I wanted to visualize that. And this was before you can just go to a prompt and say, show packets flying around from China and stuff, stuff like that. So I taught myself 3D animation. And we also do a lot of videos on entrepreneurs, how to give advice for startups. And I was like, ⁓ I really can't say that I have a founder who did a really bad job on a panel. And here's how we should all listen to it. I would never I would never do that. But at the same time, you know, if I say I was at this conference and I saw this panel, like I you know, it's pretty easy to kind of triangulate who are who I'm talking about in our portfolio. And believe me, that's a private conversation I want to have, but I'm also trying to be public about it. So I found out I can do animation with characters. And I did a bunch of animations. And if you go back to like the early videos, it really looks like early Pixar type stuff, right? 'Cause I was learning how to do animation and stuff. But the animation technology has progressed so much. Right. Yeah. I created this V Ron character that I can literally like right now, I've got Claude working on four or five scripts for ⁓ for V Ron. You know, the Pope just came out with an AI ethics thing. I read I read the first half of it. I'm like, this is great. Go write a script on this, make all the imagery, do that kind of stuff. So could I do that in person? I could. but I'm really getting a following with the V Ron stuff. And then for the stuff that I can't really talk about, for example, you did a great interview with Brian Martin, right? The vulnerability historian, right? Yeah. It's really hard for me to come up and just basically say, Sis is not doing a great job or the White House is not doing a great job, or this policy should have been here. But putting it in animation, it appeals to more people. And I can also do comedy with it. I have a comedy guy called Gary Sinfeld. He can do humor, whether it's people like ⁓ ⁓ Canvas getting hacked during finals week. You know, that's the kind of stuff I can do from a humoristic point of view. That's not me pointing the finger, still kind of raising awareness of this stuff. So I'm finding a great deal of enjoyment and following using the 3D animation. Plus it gives me first hand experience working with AI. What can it do and what can it do? How good can it go on? So yes, I appreciate you bringing V Ron up. I thought about a way to bring him on this show, but well the technology's not there yet. It's coming. Hi Ron, I heard you talking about me. Hey V Ron, go back into the cloud. You are not needed for this interview. speaker-0: No, when I listened to Brian Martin's analysis interview, I was like, whoa, is this Ron saying this or is this we Ron? And I'm curious, do you prompt it in a certain way to guide it? These are my opinions. speaker-1: Absolutely. So, like for example, the the Pope being Catholic, I'm gonna read that script very, very, very thoroughly before I even try to record it. Whereas, for example, with your interview with Brian Martin, I wanted to get the best, most controversial stuff and make sure that Viron wasn't like saying, This is good, this is bad. It was just he's just factual saying this is what Brian Martin said on the inter interview. And ⁓ you know, kind of leaving it at that. And and that's it gives me a lot of ability to kind of just put that information out there. At the same time, you know, when the White House comes out with a executive order or a finding about, you know, what they're dealing with China and stuff like that, you know, I can also use VRON to do that and not necessarily look like I'm ⁓ politically supportive of of of of this administration or the previous administration. You I I really Just try to be independent and ⁓ doing doing that sort of stuff. So it gives me a lot of latitude to go and and test content and put content out. speaker-0: Have you gotten pushback for some of the commentary from here on or is it like always free, you know? speaker-1: ⁓ the only you know, I mean, look, don't if you ever have a channel, don't read your comments, right? You know, there's always somebody who's who's saying this or saying that. ⁓ you know, look, AI pulls lower than the White House does right now. Like people are very concerned. 'Cause I'll get so I'll get, you know, for a video that gets like a hundred thousand views, I'll get a clank or shut up clank or comment, you know, something something along those lines. And ⁓ I think that's funny. It really I I really feel like I can, you know, also experience what people are experiencing because some people just don't trust AI. They think it's going to take their jobs. They think it it could be full of full of errors and stuff like that. So it's it's again that from a social point of view, it's a really interesting thing to get involved in. speaker-0: So, ⁓ Ron, let's switch to your time post Tenable. You ⁓ know, you've been in one of your biggest contributions post Tenable is venture investing, coaching, mentoring, startups. I remember when ⁓ Tenable did its first series A, it was a 50 million series A. One of the massive, one of the biggest series A at that time. And I remember you were ⁓ bootstrapped for almost a decade or so. Tenable didn't take any venture money in those days to the extent possible. I'm curious how as, but now 50 million series ⁓ is not a big deal. But in those days it was probably the top 10 venture, series A ⁓ deals of that time. But now series A, know, Tenable probably had thousands of customers. and millions of dollars in ARR before it got to 50 million series A. But now you could have sub one million ARR and still get a 50 million series A or sometimes even 100 million series A. You just put an AI on top of your company and you're like, boom, I don't know if you saw the shoe company, the Allbirds. They put AI in their name and it went off. I'm curious, given your deep experience in venture post-tenable, how has that business changed from your point of view, the way you see it? speaker-1: Yeah, so a couple a couple comments there. So tenable, we were extremely successful with, you know, generating revenue, supporting customers, just hitting the market at the right time. And when we raised those rounds, the $50 million round, the $300 million round, not only were they record setting at the time, but they were direct secondary sales. And what that meant is that money went to the employees. Typically today, if you're a million ARR and you see a headline, hey, somebody raised twenty, thirty million dollars, that goes on to the balance sheet of the company, right? There might be a little bit of secondary sales for for the founders, maybe some key people. But with those rounds, we had that experience of bringing employees into a room and saying, This is what's happened. You might have enough stock to buy a house, pay off your s your student loans. ⁓ You know, become a millionaire, right? We had a range of people that were that were doing that. And very, very, very unique. And with that experience, when I talk to founders, when I talk to startups, I'm always imagining how is this company going to exit? Is the founder prepared for the financial management of becoming a millionaire? Are they prepared to guide their employees to do that? It's really tough because if you're a crappy founder, And you're just greedy and you have a lot of equity and stuff like that, you know, an option pool or something like that for your employees might not be that that inspirational. But if you create a company that's worth, you know, $500 million and the employees have 10 to 20% of that, if you include the founders and stuff, that's a significant amount of wealth creation. And a lot of founders kind of miss that opportunity to kind of say, There's ways to exit before, you know, you're super, super successful. Or before you have to raise two or three more rounds, right? When you see a company does a series A, a series B, Series C, boy, maybe that company's great and they're making money and increasing value at every step of those ways. Maybe they're doing these are dilutive rounds. It's hard to say sometimes, you know, what is going on with some of these these companies. ⁓ I give you I again, I can't name names, but you know, there's a company. Yeah, really. But look, there's a company we passed on. speaker-0: Maybe a WeeRawN episode. speaker-1: I said you're never going to be able to raise. Within a week, they raise $30 million. And then guess what? Three years later, revenue is still about less than a million ARR. I see that a lot in this industry. And that's the kind of thing I want founders to avoid, right? If you're raising a dollar, you better be putting that dollar to work and making at least a dollar from your customers, right? Because I c if you can take the $20 million investment and turn it into $2 million of revenue and you still need more money to pay for your company. That's not a successful business. And I'm always reminding people, you know, put the customer first. You have to have a product that people want. And then look, today with AI, what I'm telling people, whatever you do is almost irrelevant because you can make it with AI. So it's more important to engage your customer, support the customer, perhaps even merge what you're doing with other people who have similar types of customers so you can create value. You can't use a prompt to create customers. And that's gonna be the biggest thing differentiating startups now into the next couple of years. Do does anybody really care about what you're doing? And that's ⁓ that's kind of where we're at right now. speaker-0: What happens, you bring up an interesting point in the sense that you can literally create anything you want. And you could, there is a feeling, hey, I can cloud code my way out of this. And I've seen this in our discussions at Contra as well. Hey, why can't I cloud code these things, and so on and so forth. And the reason, typically, founders go and raise is because they need to hire, they need to do sales, marketing, and so on and so forth. But lot of these things could be automated or, you know, the need for hiring is not as much. the need for raising a bunch of capital is also not that much. So what happens to, in the age of AI, what is the role of the VC? The capital needs, I mean, unless you're like training big models, you obviously need a lot of capital, right? If you're building data centers, you need a lot of capital. But if you're building software, You probably don't need as much capital. And I've seen in the competitors in my space, raising $40, $50, $30 million. Now I'm saying, why are you raising all that money? What are you going to do? Going back to your point, if you take a $30 million investment, you probably need to make $300 million, $400 million, or get to that scale. So what happens to this venture side of the business when the need for capital is not as speaker-1: Yeah, so it's a great question, right? So, you know, I have this thing called the five-side pitch deck, right? What problem you solve? How do you solve it? Show me some proof. What's your ask and what's your victory conditions, right? And we invest in a lot of different companies, right? Some people in our portfolio are primarily doing business with the Department of War. Some people in our portfolio are doing business with with the the consumers, right? People who have phones. There are apps on phones, you know, that sort of thing. So the go to market is very, very different for those things. The ask. might be, gee, we need to do a lot of marketing to push our app, our thing on this consumer thing, like the Apple iPhone market, you know, that kind of stuff. ⁓ maybe the ask is, look, we have a great product. We really need a human sales force. You know, maybe the ask is, hey, we actually have a lot of engineers, but they haven't been using AI. We need to transform this process into an AI first. you know, engineering teams. I'm seeing all sorts of changes going across out there. ⁓ we have a company in our portfolio, again, I don't really want to say they were doing a lot of what I would consider services and they had a wide variety of scripts that were used in these services. And now they are bringing all that into a unified kind of SaaS platform. That's, you know, can could they do that with their budget? Do they need to raise in this case they're doing it within their budget, their cash flow. So they're they're fine. ⁓ You know, the other thing to think about is, you know, coming out of COVID, coming out of some of the the ⁓ economic downturns we've had ⁓ a couple of years after that, most companies what I consider are their steady state. They're basically cash flow neutral. Maybe they're growing ten percent, twenty percent. And that's because they had to cut and and do that. We you know, we have some of those companies in our portfolio. Most most cyber funded companies like that in their portfolio. What do you do in that case? My advice is like, look, you can raise, but maybe it's not at a term that you like, you have to give up too much if you're a company. So you need to do things to increase your revenue. ⁓ I you know, one good example of that in our portfolio is we have a company called Threader, and they actually bought, you know, the highest DNS security business. So now they can do inline blocking with a hardware device and secure DNS, which just, you know, they got some customers with that. That is the model what I tell companies who are trying to grow. Put your customers first, try to do MA that's going to make you ⁓ you know, a bigger a bigger base of customers and offer something that complements your product. speaker-0: On the topic of M &A and maybe acquisitions, have listened to your interviews where you say you see these big numbers coming out. This so-and-so company got bought for 500 million or a billion, but the founders actually didn't make a bunch of money. It was essentially some kind of financial engineering that happened behind the scenes. And I see this all the time. There is a perversion of capital in the sense that... The companies like the companies that you built, in a product first, customer focused first, let's get to ARR, let's build a proper business and then get to a point or get to an IPO. I see less of that and more of hype. There's more of a lot of marketing hype. Let's go and get our pictures in front of NASDAQ and make a very splashy news event. ⁓ And then it get acquired for 400 million or 300 million, but it is essentially the money is just exchanging hands between investors rather than the founders or building a proper company. And my co-founder Sasan experienced this at CrowdStrike. was doing a due diligence for a company and he was the head of engineering at product and he passed on. said, hey guys, this product doesn't work, not functional. There is no way we can use it here. Two weeks later, company bought for $300 million. I don't know what you have to say on this, but you've probably experienced this from your point of view as well. speaker-1: So it's it's kind of hard to relate because most people are not founders. Most people have not done what you've done, which is you've you said, I'm gonna take a risk, I'm gonna start a company and and and and do it. And as soon as you start a company, you could be on a track to sell the company for a headline amount, $100 million, $300 million, $30 million. It's crazy that that you can do it, but but the story is look, 99.9% of the companies never get past $100 million in revenue. They either go out of business, they get acquired, they just can't grow. And and so it's that's a really difficult, ⁓ it's a really difficult ⁓ thing for people to get their their their heart eyes around. And if you're gonna incentivize somebody at a company like that, you're also competing with Google and OpenAI. They're throwing around salaries big enough that if you gave somebody one percent of your company and they work for you for like five years and you're sold for three hundred million dollars, they might take home the same amount of money working at Google. So it's it's it's a really interesting thing. What's changed though is the advice I used to tell entrepreneurs that look, once you build a technology, before you build your business, you have an opportunity to sell. And that might be the maximum amount of money return that you will ever make for you and your employees. And it's just crazy because you might have no no revenue yet, but if you have a unique, defendable set of intellectual property, a thing that's really hard for somebody to duplicate. They might somebody might buy you for a lot of money where the founders might still own more than 50% of the company. You do a couple rounds of fundraising, though, founders are diluted. Maybe you don't get the best deal going forward. Maybe you get this amazing deal. It's it there's there's all sorts of stories out there with ⁓ with this. But with AI, I've said, look, whatever you're building right now, it's tough because somebody at Cisco, somebody at ⁓ you know, Microsoft, whoever these acquirers are checkpoint, whatever. somebody's gonna be in there saying, I can build the same thing that that just give me a give me 10 weeks, right? Give me whatever. And that's a tough that that kind of ⁓ upsets that. So now my advice for founders, get some customers. Like you can't just have technology. You've got to have customers that are using it and paying for it and are happy for it. speaker-0: You give a lot of advice on startups and one of your best or most prominent videos is the five slide pitch deck. You you said, know, what problem are you solving? How are you solving it? What are you going to do with the money? What proof do you have? And then what's your vision for success? It's pretty straightforward, pretty self-explanatory and understood. But ⁓ not many people... are internalizing it and they still, I mean, you probably even now see pgTex that are all over the place, right? From your perspective, what are some of the common mistakes founders are making? Even after you, I think you promoted this for four or five years now. is... speaker-1: Yeah. We we did it out of a little bit out of frustration because we would get pitches from companies and we couldn't tell if it was a nonprofit or a commercial company, right? It's especially it's i if it's kind of fuzzy. Because at the time we were doing a lot of these competitive grants for cyber nonprofits. And you would see somebody who has a cyber training for maybe veterans, and we're like, is that a commercial company? Is that a nonprofit? It was so you know, the big point of the five slide pitch deck was to get to a no or a yes. as quickly as possible. Because a lot of these funds, people don't realize that when you're in a meeting and somebody says yes, somebody else at that company has to go tell your story. So if you've got 30 slides and they're telling a different story than what you're telling, it's probably not likely you're going to get a fundraise, you know, from ⁓ from from from that that company. Now a lot of the mistakes people do is they put other things in there. Like they tell me how big the market is. They tell me that they've got four advisors on their on their team. Like those are details that are gonna come out after you know, there's a transaction, right? You don't need to lead with that, right? And then sometimes people are like, like I literally got I I I don't want to say names, but I got I got I had a a female CEO, ⁓ founder who said, Hey, so and so invested our company. Would you want to invest? That's a tough that's a what what do I do? Because if I say no, it might get back to the the the the person who's a prominent person in the industry. They didn't want to invest. But that's not a reason to invest in a company. So you're putting me in a tough, tough thing. And then the second thing is, ⁓ we just close three customers. You know, do you want to do you want to meet us? It's like it's still I still don't know what problem they solve. Is it competitive with any of our portfolio companies? That that sort of thing. So I need to know as much as possible before we even take a meeting. And it's the same across all the other funds. Like a lot of time people don't realize that most of these cyber funds, they talk to each other. And if somebody passes on something, It's not necessarily like you're blacklisted or whatever the right phrase would would would be. It because somebody out there is gonna want you to th this is one of the big things we started Bulatech Adventures because we Cindy and I had invested in all these funds and you know, we had some opinions on what founders were investable and what markets were investable. Some of those companies didn't r some of those VCs didn't like us. So we said, look, we should go start our own fund and and do these things. So there's so much talent out there, but there's also a lot of people who can talk themselves. out of or investing in a company. speaker-0: And are you still seeing the same kind of mistakes that you saw in the early days of, you know, five slides, which they were custom with the founders come in with, you know, Hey, so and so invested in my company, you should still invest. ⁓ Or are there new kinds of problems that you're seeing? Because the thing I wanted to touch upon is, thing I wanted to touch upon is, because building companies in the age of AI is completely different. And you've talked about this in your interviews there. And the thing, the line that comes to mind is there is no easy exit. The age of AI. There is no easy exit in the age of AI. So I want to touch upon that aspect of it. Like how does building in the age of AI change? speaker-1: Yeah, so the the the big thing with the AI is if you're building your technology on AI, you know, you might be building a great product, but you're dependent upon that AI. Who what's who's got the real innovation there? Who's got the intellectual property? If you build a cyber product and you're talking to Cloud, you're talking to Anthropic, talking to OpenAI, talking to Gemini, whatever you're talking to, if that is your core IP, you're more of an integrator than you are an innovator. And that really gets people frustrated. But we've seen this pattern with the cloud. You know, so if you write your own ⁓ for example, your log analysis tool, your your parser, your your, you know, whatever, they gotta run somewhere. But if you build everything on Amazon to the point that you use all of their APIs, you might be able to come to market really quickly. I tend to think you're also an integrator. You know, you're really dependent upon the pricing of Amazon, the the the the fluctuations of Amazon, their technology decisions. And we've seen cyber companies that are all in on Amazon and guess what? They're stuck there. They can't go to Google. They can't go on prem. Because if you're going to get big, whatever your product does, you got to have a an MCP interface for it. You have an API for it. So your GUI has to look nice. It's got to work in a container. It's got to work in an appliance. And and by the way, you know, if I'm a no ⁓ Amazon, shop, I got to be able to move that to as you're move. So you have to do all these things as a as a as a startup. It's really interesting to figure out that impact. I I just, man, it's tough. I I actually had a company pitch me and they claim that they're doing an AI thing that's somehow better than Claude and Anthropic. But at the end of the day, they're wrapping Claude and Anthropic. So it's like you're even then you're still dependent upon these things. So again, what problem do you solve? How do you solve it? If if if you're leveraging AI to solve that, Man, I don't know if that's an investable company. And that's controversial for a lot of people. speaker-0: Do you think that, you you mentioned the cloud transformation where companies went and integrated with Amazon and then they had to go with Azure and so on. Do you think the AI transformation is similar compared to or compared to the cloud? speaker-1: Absolutely. It's absolutely similar. And so like look look, if you're building your product and your engineering team is using anthropic, using ⁓ I mean perplexity, you're using whatever, whatever, you know, cursor, whatever whatever people are using, look, that's great. At the end of the day though, if your actual product, the thing you ship, is dependent on anthropic for its core value, what's the barrier to entry for another company to come in and do that? So And then how do we even value that, right? Because you're really a rapper for anthropic. If you're a rapper for anthropic, it's you're like I said, you're an integrator. You can make money, but it's almost like you're in the services business. And and that's that's kind of the way I look at it. Now, we've invested in some companies that are very dependent upon anthropic to do certain things, but the people who are using that are doing things we have their very first. They're they're they're it's the first of their kind, you know, kind of kind of thing. So we have an animation company. That's powers V Ron. You know, that's, you know, they have so much IP on top of that. Yes, they're dependent upon anthropic, but they're also dependent upon 1111 labs for, you know, for voice. They're dependent on other things for for ⁓ you know do doing types of analytics. My point is if you are a wrapper for multiple services, you can probably create value. And I've seen some companies do this in cyber. I'm seeing people do it in healthcare. We have a healthcare investment that's in stealth right now. They're doing some amazing stuff with their own technology and with anthropic. So it's it's like the what problem you solve and how do you solve it? It becomes very easy to say, hey, that's intellectual property that the customers are gonna buy. And someday somebody might wanna own it because it's very, very unique and hard to reproduce. speaker-0: But Ron, the kinds of companies that will get created out of AI will design the AI natives. For example, when ⁓ iPhone came out that created the Ubers of the world without iPhone, Uber probably would not exist. So the new companies that come out, have almost AI as a substrate layer where the reasoning and the thinking, this was simply not possible before. Most of it was very rules-based. You had to code every aspect of your business process and so on. So my sense is these kinds of companies, the new kinds of companies, AI native companies will still, they will get created, built on this substrate. mean, they could obviously be seen as a wrapper, but obviously they have to build their IP. My question is, how do you then expand? How do you then grow the companies in this AI native world? Is this because the historical model was land and expand. You land in with one. product, one solution, one niche, you go in, I'm going to solve this for you. You get that, you make that customer happy, then you expand to that, Jason, what else can we do for you, and so on and so forth. So is land and expand still a viable strategy for startups in the age of E.I.? speaker-1: So I I I I think it is. So the the question really is what problem are people solving? And and when you mention AI, people are like, we need AI guardrails. Well, there's a lot of companies doing that. There's a huge gold rush of companies that are saying we can control or detect how you're using AI. My my issue with these a lot of these companies, we haven't invested in in a lot of we did someone, I'll talk about that in second. But my issue with a lot of these companies, there's so many ways to interact with AI. Trying to say you're detecting it all or or stopping it all is really tough, right? If you have a BYOD computer, you know, Microsoft might put copilot right on that computer, right? ⁓ you know, can I go to the web interface and interact with Gemini, you know, in my private Gmail? You know, that's there's so many different AIs that that that that are out there. It's interesting. how do you want to detect it? How do you want to enforce it? One thing that's really interesting though is for people who write their own LLMs, it's a completely different conversation. Where was the data at? Is the data good? Is it clean? Is it sovereign? If we're gonna spend a half a million bucks to train a new LLM, what happens if it comes out and we forgot to put this guardrail and we forgot to do something like that? So this type of interpretability, I think, is the future because people don't really wanna rely a hundred percent on anthropic for core decisions, right? They don't want to rely on open AI. Now, now some companies will, but if you're Citibank, maybe that's not good enough. You have to maybe train your own LLM. And this is a whole new world of doing things like that. We have an an investment in a company called StarS here. They literally can take an LLM off a hugging face, make it faster, ⁓ you know, add guardrails, add add that type of thing. And the the the technology is called the interpretability of that. Again, it's different than using AI and trying to police it versus creating an LLM and trying to change it after. But those that's kind of how I see this, this industry right now. speaker-0: Do you think the, know, for example, in cybersecurity, there's a lot of platformization from an end user perspective. They either go to Palo or CrowdStrike or some of these, and I think there is, see a parallel of that emerging, entropic, Gemini and so on. So one way to look at this is all these platform companies will either bake that capability into their product. Like, you know, this feature, you know, whatever startup you're building becomes a feature in their product. So they buy it. Or the other way to look at this is a startup expands, does something new, expands, and then, you know, builds the new platform that is going on. And I saw this in the CRMs of the world, right? Where you start with the one use case in the, like the HubSpot, you start with one use case and then, you know, you expand, expand, expand, you serve a lot of these. ⁓ Do you think ⁓ the platformization and the value concentration will go into these big companies or there is room for smaller companies to evolve and then ⁓ make something successful out of speaker-1: Yeah, so we did a couple of videos, live videos, not V Ron at the beginning of the year. And and one of the things I I talk about in sort of these predictions of what's going to happen over the next couple of years is indeed this platform is platformatization, right? So one, ⁓ everybody's gonna do everything. Now they're either gonna be acquiring other people or they're gonna be building it with with AI. And, you know, what does that mean? Well, you know, is CrowdStrike gonna be able to do vulnerability auditing? They already do a little bit. contenable detect malware, well, they've already been doing a little bit of that. You know, it's going to get interesting to see what these companies do to expand what they do for customers. And this goes back to your land and expand that. But the second thing is like, look, this is a good thing. If you have a platform company, I don't care if your checkpoint, your CrowdStrike, you know, I my favorite question to ask sales engineers is like, what percentage of the NIST cybersecurity framework do you cover with all of your products? And increasingly it's like the answer is like 80%. 90%. ⁓ and if you're an MDR or an MSSP, it's 100% because you know all of these services that you're offering are kind of kind of interest interesting. So I think what's going to happen next is that you're going to have this ability for somebody to say, I not only have instrumented all of your network, but I can compare that to all these other customers I have. Checkpoint's got a lot of customers. Tenable does a billion dollars in revenue, right? CrowdStray's got a lot of customers. The point is, is that if you can instrument an enterprise, whether it's a small business, a large enterprise, with your platform, you can then really start making some decisions about what is a real threat? Do I have a control in place? You know, do I have compliance issues? And you can give that feedback to the CISO. And I think in some cases, if you put AI on top of that, you might replace the CISO. So I actually said, you know, CISOs watch your back. So my third prediction, I think these companies Are going to come in and say, look, we can not only can we platform what you're doing, but we will be, you know, we will do everything. We're going to make these decisions for you. And why? Because we've got AI, we've got all these customers and that sort of thing. So platformatization, even though it's going to look where the cyber industry is going to look like the auto industry in about four or five years, it's going to be a good experience for the customers. It might be a bad experience for people in cyber, you know, because if they're not going to be needed at these companies, where do they go? Maybe they go to CrowdStrike, maybe they go to these other ⁓ D Rs, but we'll see what happens. That's that's where I think we're going as an industry. speaker-0: If that is the case, how do start-ups build modes in the age of AI? Because you don't have the data, you don't have the customer. speaker-1: They gotta have customers. This is why I'm saying what you build is interesting and unique. That's cool. If you can't attract customers and grow your business, you're not going to be relevant. And that's why I say, look, if you do this niche thing, because that's that's one of the other issues with cyber, we've been around for a long time. You know, there's new patching companies, like we're investors in Automox, but patching's been around for a long time. You know, there's there's there's a lot of CI C D companies out there, there's a lot of ⁓ EDR. lot of incident response companies, right? So if you're going to do something in that space, it becomes very niche. You know, like there's ⁓ you know, companies that just they're they're starting to do incident response on phones. That's kind of cool. It's also very niche. Like there's not a lot of demand for that. So my point is if if you're gonna do something, it's got to be defendable. It's got to have something that people want. You have to answer every one of those five slides pitch text. If you can do that, you're probably gonna be in good shape. speaker-0: One thing you touched upon is the job of a CISO getting replaced ⁓ by the service companies. My question is to you, what is the future of jobs with AI? Are we seeing a situation where service offerings will take out full-time jobs, even the CISO? speaker-1: Yeah, look, the way I look at this, if you think about a smaller company and they want to be CMMC compliant, they go to a a service like ⁓ a Drata, ⁓ Vanta, ⁓ or even like look, look, we're an investor in an MSSB called Bemo. BMO can get you CMMC certified if you're a Microsoft shop. They can do all the configurations, they can do all that. So is it as good as having somebody like, you know, Reliquest or Arctic Wolf with your own SOC team looking at that? But look, if you're a 50-person company. Working with BM was probably state of the art for somebody of that that size. But look, as you go up into small business, medium business, enterprise, large enterprise, Fortune 2000, Fortune 100, you're not going to have a one click, we're compliant. There's no way. So those people are always going to have something like a CISO that has to do with policy decisions about data flowing, data training, partnerships. There's so much to do at that scale of a company. You we're we're never gonna like not have a CISO at these Fortune two thousand companies. But look, when you go to these small companies, they don't have any cybersecurity right now. So they're probably gonna have it outsourced to that. Somewhere in the middle, there's gonna be conflict, right? Some people are gonna be like, Hmm, hey, instead of just outsourcing everything to this MSSP for monitoring or this MDR, why don't we do everything and reduce our staff? Maybe, maybe even get rid of the CISO. Like I can I really do see those questions happening right now. speaker-0: So what do you recommend to the CISO who is in the CISO chair today? ⁓ Should they take like a front seat for these AI decisions or should speaker-1: Well, look, I've always said, look, there's a lot of great CISOs out there. And for some businesses, if you have a huge like there's some SISOs who have like 20 other field CISOs working for them, like those are large organizations, right? Be aspiring to be the CISO there is probably your your your career goal of doing that. But if you're a small business and you're an IT, like I think you should be aspiring to be, you know, the head of operations, even the CEO. Like the sometimes security people know the business so well. They might be able to do marketing better. They might be able to do other things better. And I've always kind of felt bad that cyber people kind of say that the best job we can have is CISO. Boy, I think operations and CEO is a good job because if you're look, if you're CISO, you gotta touch everything. You gotta touch marketing, legal, you know, IT, budget. ⁓ there's so many things that you have to touch in that business. How do our customers engage us? If all of that's happening and AI is controlling all of that, who better than a cybersecurity person? To be in charge of auditing that and running that, making those decisions. So I see the CISO role being replaced with what are the policies the AI is doing for our business and how it flows and how it works, you know, what apps we're using, what it has access to. The the the the cyber community is is are the people who should be running that. speaker-0: So do you recommend and the CSUs take head on charge of all the AI initiatives? speaker-1: What what I'm saying is if you're a CISO, you should be fighting to run any AI initiative you have in your company, whether it's exploratory, whether it's writing your own stuff. ⁓ there's a couple friends of mine at large energy companies. They literally are the CISO and the head of AI operations. And that's boy, that's that to me is the future. Now, I don't think that it's gonna last forever. It's probably gonna be AI operations in the long run. It's gonna subsume most of the cyber operations. ⁓ But right now and you know, if you're not lobbying for that role, you're gonna be out of a job because I think your MDR, your MSSP, your vendor is gonna replace you. speaker-0: Interesting. Ron, final topic. Let's talk about the future of cyber offense and cyber defense. This is both near and dear to both of our hearts. ⁓ You obviously built companies around this. When I started at Tenable, the time and the cost required to build exploits was hard. We had to learn IDA Pro, reverse engineering, figure out Like for example, when these new vulnerabilities would come out, we had to spend like time, days to figure out how to exploit this safely and then write an SS signature for it. And now it is possible to write reasonably working exploit with a prompt. This is a CV, this is the patch. What's the best way to exploit this? And these models are good enough to ⁓ go out and... give you an exploit and we are part of, for example, cyber verification program. can see this firsthand. These models are getting better at ⁓ crafting the exploits, not necessarily in terms of weaponizing it, but you can still see how it is going. If you're a relatively skilled attacker, you can now go from ⁓ taking a vulnerability information and then going from there. So my question to you is, what is the future of cyber offence? What happens from here? What does the future look like from your point of view? That's the first question. And then the second question is how do organizations defend against this AI native offense that is coming your way? speaker-1: Yeah, so look, that's like a whole hour conversation, right? But let's I I can summarize it pretty briefly. So one, look, we might elevate cyber command to cyber force. But if you said, do we have a civilian agency that's already doing offensive cyber? Yeah, it's called the National Security Agency, right? We have another one called the CIA, right? They do a lot of offensive cyber. And do they support Cyber Command? Do are there's do they have the right titles? I mean, absolutely. And for the first time, You know, we've ever we this is this administration has publicly acknowledged. We're using cyber in these operations, right? Whether it was Venezuela, whether it was the ⁓ the the the bombing campaign in Iran, we're using cyber. What does that mean? Look, when you do offensive cyber, a lot of people assume it's just like direct hacking and and that sort of thing. And then may you know, maybe there's some of that involved, but the tradecraft could be a lot more interesting, right? Do we have a human in the loop? working for us, right? Do we have the ability to deploy something? I mean, we there's a article came out yesterday, a parachute can drop a cyber munition and and and do attacking, right? So a lot of times people don't forget or they forget that in war, it's the entire triad of confidentiality, integrity, and availability. Maybe we're not hacking in and spying on people. Maybe we're preventing the email from being sent. Maybe we're preventing the email from being sent with jamming, with a physical attack. That's all under cyber command, special operations, and that sort of thing. ⁓ are we gonna do more of it? Maybe. There's ⁓ there's a couple of articles that have come out. I'm doing again more research for for for V Ron, ⁓ where they talk about look, most of these plans, if you're gonna do a cyber attack on a facility, you probably have six months, maybe a year to plan for it. And and look, if you're doing a bombing campaign, it's very similar, right? We don't just like wake up one day and say we're gonna attack this country. There's plans. way ahead of time and maybe even training, you know, that goes with that. That's how the modern stuff works. ⁓ but if you want to talk about defense and you know what that means in the age of AI, I think it means a couple things. You know, one, I think modern businesses have to realize that cyber hygiene, you need it, but you can't rely on it. If you can't patch fast enough, if your EDR doesn't have a signature for the latest attack, you're going to have bypass. And if you're attacked by a nation state, your layered defenses of controls are not gonna prevent them, possibly not even detect them. So what do you do? I think you have to invest in separate networks, whether it's an air gap network, a cryptographically separated network. ⁓ but we had the technology to do these things, right? Whether you're a Z scale or show up using Tal Scale, like in our portfolio of something called Enclave. Can you take your core decision team? And have a separate network that is literally separated from ⁓ from the internet, from any content that might come in. Once you think about the internet is that any content, whether it's a network connection, a packet, a file, that could be an attack. So if you have the ability to to segment that and remove that, you're much better off at being able to defend yourself from China, from Iran, from Russia, or possibly even industrial espionage. So I think these separate air gap networks, these separate cryptographically networked is gonna be something that people are gonna use mostly to keep AI out of things. I wanna make sure that none of this data gets to AI. But look, a byproduct of it is you're gonna keep China and Russia out. People are going to be more afraid of giving up their corporate data to the AI companies and they're gonna implement these things as air gaps. And a byproduct is China and Russia are going to have a lot harder time hacking into them. speaker-0: Ron, what you said makes sense for the government, like the NSA, they have been doing offensive security for a long period of time. My question was more targeted towards the attackers, ransomware, ⁓ as a service company. It was very difficult to create exploits to go in and compromise systems. But that equation would change with ⁓ these AI-native tools that would come out. So my question was more targeted towards that, what happens in that scenario. Let's say about a... speaker-1: It's always gonna happen that ransomware is gonna increase, but it hasn't yet. As a matter of fact, paying per ransom is going down. The cost of a ransomware event goes up because you have legal, you have to, you know, notify your customers and you have to do, you know, s understand all the recovery stuff. So the cost of a ransom is going up. But the actual ransomware actors have had to go into smaller and smaller accounts, and those accounts are paying less than than than than normal. ⁓ and if you if if you look at some of the big ransomware events, like I don't I don't know what Canvas you know paid to the to the ransomware actors, I don't know if that's public or not, but there's a lot of big payouts for people who've made mistakes that skews the ransomware thing higher. But this the story there is basically look, these people who've been hit with ransomware, they got religion, right? So maybe there happen to be CMMC compliant, maybe they have to be SOC2 compliant, maybe it's PCI, maybe who who knows what it is. Post-ransom victims. tend to have a better posture against future attacks going on. But look, I think the whole industry is waiting for like a wave of AI enabled zero days and stuff like that. We're not seeing it. There just hasn't been that much of an increase. speaker-0: What, on that topic, what happens to vulnerability discovery and reporting in the age of AI? Like we were used to maybe 100 vulnerabilities a day back in the days of early days of Tenable, and we would decide to do five of them that were like Microsoft or Adobe and so on. The Glasswing update just came out. They said they found 10,000 critical and high vulnerabilities in them. They were scanning thousands of open source. ⁓ repos for working with maintainers and so on. Do you sense this happens for the next year or so? There is a massive explosion of vulnerabilities and then it plateaus or do you think... My biggest concern is the chaining of vulnerabilities, not necessarily the... Because typically you would find a remote code execution vulnerability break into a compromised system and so on. Now you could chain multiple medium severity vulnerabilities. The attack chance would increase, but the vulnerabilities may come down. I'm curious what you think. Do we see a plateau or do we see an explosion from here? Things get better or worse from here. speaker-1: So I think it it's gonna be difficult. So so look, I don't have access to mythos, but I've talked to companies who've had had access to mythos. And what they're telling me is that look, they found a bunch of vulnerabilities in their stuff, they're gonna fix it, issue patches, and and that's a good thing. But if I said, Do you think there's more vulnerabilities in there? Of course there's more vulnerabilities in there. We're we're not done yet. ⁓ you know, and if mythos found it with this level, what happens if mythos two comes out and it can find, you know, even more? So when you think about secure by design, I Would like to hear more companies saying, you know what, we're going to completely rearchitecture our coding to do minimum tax surface stuff. So for example, when when you code as just a simple C program, Hello World, right? It pulls in a library. Well, that library, you know, might have APIs that your code doesn't need, but it it just got linked and it could be exploited. So is there are there new technologies and new projects out there? And I've been pitched some of these things that have minimum viable attack surface for the libraries you want to include, right? That's that's a game changer. You know, there's another concept called unikernels out there, right? Instead of having a container that runs on ⁓ you know, a ⁓ my gosh, ⁓ you know, a container platform, you know, Docker, you know, that kind of stuff, ⁓ maybe you could have a VM that just has the APIs that your program needs in in the VPN or VM, I was in the VM. And my my point is you're reducing your attack surface to to do these things. But when I hear about a company that says, okay, look, our c our code's pretty ancient. We've got a lot of bad structure here. We're going to completely redo it. And at every step of the way, you know, there's boundary checking, there's variable checking, there's all these things. It's going to be secure by design because if somebody fails along an API, there's going to be all these other checks that that that stop that. When I hear companies talk about that, I get a lot more confident that. we're gonna have more secure software. There's no question that we are gonna have more secure software because of mythos and stuff, but are we still gonna have more vulnerabilities unless we have really well written programs, we are we we you know, we we will. speaker-0: Do you think most of the programming is done with AI in the future because of speaker-1: Well that that's the question. So, you know, I'm on a mailing list or a a signal list. ⁓ I think I can quote it, but Chris Weisopel's on, right? Vericode. And he's like, you know, could you ask Claude to write code that it can't break into? Right. That's a good good question. Yeah. But I've seen I've seen code written. I do a lot of shell scripting for my what I for my animation. I see a lot of bad practices every now and then. Every now and then it's sort of like, ⁓ you're including an API key here. You should have changed that. I'm like, I did change it. Why why do you still have access to it? So so it's it's it's crazy. But you know, the other thing that's going on is people are just hacking GitHub directly. You know, they're they're making commits, they're doing things. That's a hard one to find. ⁓ you know, if you look at that copy fail exploit, that was like three different things that you had to chain together to get root. ⁓ I'm working on a there's a Linux backdoor story where somebody added a ⁓ you know, if if you you know UID equals zero instead of it could be zero. And it and it says that so there's so many potential attacks with GitHub. that we're dependent upon, that's crazy too. speaker-0: And because of AI, lot of non-coders and non-programmers are going to be publishing their code to GitHub. And it may or may not be safe. Maybe they expose the environment variable. Who knows? The .n file. speaker-1: There's there's like like for example, the IoT devices. It used to be that you could never ever on your own replace your firmware. But you you could literally say, I bought this device. I'm just gonna tell Claude to to to write code for it that does this and then let me fix it. So that code, that new code might have vulnerabilities, but it's not gonna have as many vulnerabilities as that old code. And maybe that code is unique just to your organization. And that's a crazy thing about AI. If I start writing my own SaaS, my own Salesforce CRM. If I start writing my own Gmail, my own stuff like that, maybe it's going to be, maybe it's got more vulnerabilities than there, but if nobody else has it, how does the attacker ever really research it? speaker-0: Super fascinating, Ron. This has been an amazing, amazing interview. I'm grateful for your time. You're way too generous with your time. What's the next big video dropping from V-Ron? speaker-1: I have ⁓ I I I've got an one I'm waiting for ⁓ Rob Joyce to approve, but Rob Joyce just came out with a paper that basically said the China attacks on our ports and our phone infrastructure, it's the equivalent of like digital dynamite. So he's got a really good it's like eight or nine pages and I I've already recorded, I'm ready to publish it, but ⁓ that should be coming out next. speaker-0: Awesome, awesome. Well, thank you, Ron. Thank you for coming on Noise to Signal. This has been epic. speaker-1: Hey, thanks for the great questions. ⁓ if anybody wants to contact me, gula.tech is the website and I'm on LinkedIn. We're pretty active. Find us on YouTube. Really appreciate the opportunity to to talk about this stuff. Yeah, some good speaker-0: all that information in the show notes. that will show up.