Skip to content
EO StudioEO Studio

Everything You Should Know Before Mythos Arrives | Nebulock, Damien Lewke

A cyberattack used to take an elite team and a decade of hard-won instinct. Now it takes two people and a GPU. Damien Lewke spent his career on defense - at the DoD, at CrowdStrike through its IPO, and at Arctic Wolf - then raised a $25M Series A to build Nebulock and hunt the threats hiding between your security tools. In this conversation, Damien breaks down how AI has collapsed the cost of attacking a company, and what defenders have to do right now to keep pace. He maps the cyber kill chain stage by stage, names the three behaviors that reveal an attacker is already inside your network, and explains why 'assume breach' is the only realistic posture left. He also gets honest about walking away from a stable career to start over with no salary. What you'll learn in this video: - The three behavioral signals that an attacker is already inside your network - Why every stage of the cyber kill chain except the last is now automated, and what each stage costs an attacker - The fire marshal vs. smoke detector model for threat hunting vs. reactive alerting - How 'green flag' activity hides the most dangerous breaches in plain sight - The $0 test Damien used to know he was ready to quit and start a company - Why founders should obsess over the problem, not the solution 00:00 Intro 01:09 Love the Problem, Not the Solution 03:30 How the Security Talent Gap Collapsed into a Subscription 05:30 Quitting with No salary: The $0 Test 07:02 How One Person Actually Hacks with AI 08:30 6 Steps of Cyber Attack 09:55 Assume You're Already Hacked 11:30 The Three Signs an Attacker is Already Inside Your Environment 13:00 Don't Fear AI, Fear Inaction 13:51 What You Need as a Founder EO stands for Entrepreneur& Opportunities. As we're looking to feature more inspiring stories of entrepreneurs all over the world, don't hesitate to contact us at partner@eoeoeo.net LinkedIn | @EO STUDIO X | @eostudi0 instagram | @eostudio.official

Damien Lewkeguest
Jun 29, 202614mWatch on YouTube ↗

CHAPTERS

  1. 0:00 – 1:00

    AI shifts the balance of power in cyber—and the race to adapt

    Damien frames “Mythos”-level AI as an accelerant that enables small actors to punch far above their weight. The real issue isn’t panic—it’s whether defenders can adapt as quickly as attackers, and what comes after today’s models.

    • AI enables “two people and a GPU” to credibly target companies
    • Biggest question: can defenders adjust at attacker speed?
    • Security has a narrow window to prepare for what’s next beyond current AI
    • AI isn’t existential by itself; unpreparedness is
  2. 1:00 – 2:31

    Damien’s path: DoD ops to CrowdStrike, Palo Alto, Arctic Wolf, MIT

    Damien introduces his background across government, high-growth security companies, and academic AI research. He emphasizes consistency and discipline as the foundation for long-term performance.

    • Built cyber ops and threat hunting in the DoD; later joined CrowdStrike post–Series C through IPO
    • Network security experience at Palo Alto Networks; MDR and AI detection at Arctic Wolf
    • Graduate work at MIT CSAIL shaped his thinking about AI and security
    • Personal philosophy: show up consistently (reinforced by a 1,000-miles/year running goal)
  3. 2:31 – 3:02

    Why “best-of-breed” stacks still get breached: hidden gaps between tools

    Damien describes the operator pain he saw: companies buy top-tier security products yet still get compromised. Point solutions don’t capture cross-layer context, so attackers slip through the seams.

    • Organizations own “Ferrari-level” tools but remain vulnerable
    • Breaches often happen between layers, not inside a single tool’s scope
    • Solving compromise requires rethinking security from first principles
    • This insight became a primary motivator for founding Nebulock
  4. 3:02 – 4:02

    Attack automation thesis: tailored access operations powered by AI

    He lays out a thesis that adversaries will automate the full lifecycle of targeting and compromise using AI. Nebulock’s mission is to democratize high-leverage security work across org sizes and budgets.

    • AI will automate targeting → compromise → objective → stealthy exit
    • Goal: democratize elite security leverage regardless of headcount or budget
    • Approach: integrate with existing systems rather than replace everything
    • AI boosts both sides, but it especially lowers the barrier for attackers
  5. 4:02 – 5:33

    The talent gap collapses into a subscription—and scales from individuals to nations

    Damien argues AI compresses expertise: capabilities once limited to elite teams become accessible via tools. This cascades from individuals to companies to nation-states, and raises the prospect of “citizen hackers” unconstrained by rules.

    • Mythos-like models bring advanced capability to non-experts (“script kiddies”)
    • Security judgment still takes years, but AI narrows the practical gap
    • Adoption cascade: individual → company → nation-state (e.g., Cyber Command)
    • Citizen hackers are especially concerning because they’re not bound by geopolitics
  6. 5:33 – 7:07

    Founder conviction: quitting with no salary and passing the “$0 test”

    Damien explains the moment he quit his job to pursue Nebulock full-time. He stresses that founders must love the problem, validate with the market, and sustain conviction regardless of external noise.

    • Key self-check: “Could I solve this even if I made $0?”
    • Founder focus: obsession with the problem, not attachment to a specific solution
    • Early discovery validated the thesis and enabled the product to take shape
    • Conviction + evidence-building is essential amid uncertainty
  7. 7:07 – 8:38

    How one person can hack an org today: blending into normal behavior

    He walks through how attackers compromise everyday accounts—starting with Google Workspace—and move deeper while appearing legitimate. The hardest compromises look “green” in isolation and only reveal themselves in context.

    • Common entry: remote access to Google Workspace → Drive → endpoints → cloud resources
    • Modern attackers blend in (normal hours, valid credentials) to avoid detection
    • Key challenge: distinguishing real user behavior from compromised-account behavior
    • One patient individual can orchestrate much of this without a large team
  8. 8:38 – 10:40

    The cyber kill chain and the cost curve: what AI already automates

    Damien maps AI’s impact across reconnaissance through objectives, showing where automation is already cheap and where humans still matter. The strategic question becomes whether defenders can match attacker machine-speed.

    • Kill chain framing: recon, targeting, exploitation, persistence, lateral movement, action on objectives
    • AI has largely automated the first components (recon/phishing/exploitation/persistence trending cheaper)
    • Lateral movement and objectives still often need humans (for now)
    • Defenders have an opportunity to move to machine-speed too
  9. 10:40 – 11:10

    From reactive alerts to proactive threat hunting: “assume breach” mindset

    He contrasts reactive security (alerts) with proactive threat hunting, using the smoke detector vs fire marshal analogy. The goal is to find risk and attacker behavior before it becomes a persistent breach.

    • Attackers stay ahead when defenders only react to alerts
    • Endpoint-only or network-only views miss the enterprise-wide story
    • Threat hunting assumes an attacker is already present and looks for evidence
    • Nebulock’s origin: closing the proactive gap with cross-tool context
  10. 11:10 – 13:41

    Three indicators of compromise—and why founders should fear inaction

    Damien lists three practical signs an attacker is inside: steady exfiltration, out-of-role access, and persistence mechanisms. He argues AI shouldn’t be feared as doom; what’s dangerous is ignoring the warning signs and failing to act, especially given the current window to prepare.

    • Indicator 1: slow, consistent exfiltration that resembles normal backup behavior
    • Indicator 2: access outside role scope (e.g., intern viewing financials)
    • Indicator 3: persistence (RMM tools, new accounts/service accounts)
    • Message: don’t fear AI—fear inaction; Nebulock focuses on contextual signals across layers
  11. 13:41 – 14:53

    What founders need personally: support networks and staying human

    He closes on the human side of building a company: founders need support beyond the business persona. Damien highlights the importance of mentorship and being true to oneself while leading a team.

    • Founders must manage “you the CEO” vs “you the person”
    • A personal support network is critical to resilience
    • Damien’s dad as a mentor: deep understanding plus grounded guidance
    • Leadership goal: create an environment where people can thrive and grow

Get more out of YouTube videos.

High quality summaries for YouTube videos. Accurate transcripts to search & find moments. Powered by ChatGPT & Claude AI.