Skip to content
EO StudioEO Studio

Everything You Should Know Before Mythos Arrives | Nebulock, Damien Lewke

A cyberattack used to take an elite team and a decade of hard-won instinct. Now it takes two people and a GPU. Damien Lewke spent his career on defense - at the DoD, at CrowdStrike through its IPO, and at Arctic Wolf - then raised a $25M Series A to build Nebulock and hunt the threats hiding between your security tools. In this conversation, Damien breaks down how AI has collapsed the cost of attacking a company, and what defenders have to do right now to keep pace. He maps the cyber kill chain stage by stage, names the three behaviors that reveal an attacker is already inside your network, and explains why 'assume breach' is the only realistic posture left. He also gets honest about walking away from a stable career to start over with no salary. What you'll learn in this video: - The three behavioral signals that an attacker is already inside your network - Why every stage of the cyber kill chain except the last is now automated, and what each stage costs an attacker - The fire marshal vs. smoke detector model for threat hunting vs. reactive alerting - How 'green flag' activity hides the most dangerous breaches in plain sight - The $0 test Damien used to know he was ready to quit and start a company - Why founders should obsess over the problem, not the solution 00:00 Intro 01:09 Love the Problem, Not the Solution 03:30 How the Security Talent Gap Collapsed into a Subscription 05:30 Quitting with No salary: The $0 Test 07:02 How One Person Actually Hacks with AI 08:30 6 Steps of Cyber Attack 09:55 Assume You're Already Hacked 11:30 The Three Signs an Attacker is Already Inside Your Environment 13:00 Don't Fear AI, Fear Inaction 13:51 What You Need as a Founder EO stands for Entrepreneur& Opportunities. As we're looking to feature more inspiring stories of entrepreneurs all over the world, don't hesitate to contact us at partner@eoeoeo.net LinkedIn | @EO STUDIO X | @eostudi0 instagram | @eostudio.official

Damien Lewkeguest
Jun 29, 202614mWatch on YouTube ↗

At a glance

WHAT IT’S REALLY ABOUT

AI democratizes cyberattacks, making small startups newly hackable targets today

  1. AI is shifting cyber power by making sophisticated attack capabilities accessible to far more people, including “one person with a GPU,” increasing threats against startups and growth-stage companies.
  2. Traditional best-of-breed security stacks still miss breaches because point solutions don’t connect context across identity, cloud, endpoint, and network signals.
  3. Attack automation is already cheap across early kill-chain stages (recon, phishing, exploitation, persistence), pressuring defenders to reach “machine speed” as well.
  4. Threat hunting assumes attackers are already inside and focuses on contextual behavior patterns rather than isolated alerts, analogous to a fire marshal versus a smoke detector.
  5. Lewke’s founder journey emphasizes loving the problem, validating via market discovery, passing the “$0 test,” and maintaining personal support systems alongside CEO responsibilities.

IDEAS WORTH REMEMBERING

5 ideas

AI is expanding the attacker pool faster than most teams expect.

Lewke argues the marginal cost of key attack steps is approaching zero, enabling many more actors to credibly target companies that previously weren’t worth the effort.

Point solutions fail when they can’t see cross-tool context.

Even “Ferrari” security tools can miss intrusions if each tool detects only its slice; the breach signal often appears in the sequence across layers (identity → drive → endpoint → cloud).

Defenders must pivot from reactive alerts to proactive hunting.

Alerting is necessary but insufficient; threat hunting looks for preconditions and behavioral sequences that indicate compromise before damage becomes persistent.

Assume breach changes what you monitor and how you prioritize.

Instead of asking “Did we get hacked?”, you continually test whether activity matches expected permissions and role-based behavior, treating unusual sequences as primary risk.

Three practical signs often reveal an attacker already inside.

Watch for (1) slow, consistent data exfiltration that mimics backups, (2) actions outside the person’s role (e.g., marketing intern accessing finance), and (3) persistence moves like RMM installs or unusual account/service-account proliferation.

WORDS WORTH SAVING

5 quotes

You know, you've gone from a few score highly sophisticated groups to honestly two people in a GPU who, with enough conviction, can target a company.

Damien Lewke

The talent gap has collapsed to a subscription model.

Damien Lewke

There was a core moment where I genuinely asked myself, "Could I try and solve this problem and make $0 doing it?" And the answer was a resounding yes, and it was at that point that I knew. I was ready.

Damien Lewke

As a founder, I think what you really need to be obsessed with is the problem, not the solution.

Damien Lewke

Threat hunting exists under the auspice that you should assume breach, you should assume that an attacker is within your environment.

Damien Lewke

Mythos and AI-driven attacker capabilityCollapsed security talent gap (“subscription model”)Startups as attractive targetsCyber kill chain automation and costsThreat hunting vs alertingAssume-breach mindsetCompromise indicators: exfiltration, role anomalies, persistence

High quality AI-generated summary created from speaker-labeled transcript.

Get more out of YouTube videos.

High quality summaries for YouTube videos. Accurate transcripts to search & find moments. Powered by ChatGPT & Claude AI.