CHAPTERS
- 0:00 – 1:00
AI shifts the balance of power in cyber—and the race to adapt
Damien frames “Mythos”-level AI as an accelerant that enables small actors to punch far above their weight. The real issue isn’t panic—it’s whether defenders can adapt as quickly as attackers, and what comes after today’s models.
- •AI enables “two people and a GPU” to credibly target companies
- •Biggest question: can defenders adjust at attacker speed?
- •Security has a narrow window to prepare for what’s next beyond current AI
- •AI isn’t existential by itself; unpreparedness is
- 1:00 – 2:31
Damien’s path: DoD ops to CrowdStrike, Palo Alto, Arctic Wolf, MIT
Damien introduces his background across government, high-growth security companies, and academic AI research. He emphasizes consistency and discipline as the foundation for long-term performance.
- •Built cyber ops and threat hunting in the DoD; later joined CrowdStrike post–Series C through IPO
- •Network security experience at Palo Alto Networks; MDR and AI detection at Arctic Wolf
- •Graduate work at MIT CSAIL shaped his thinking about AI and security
- •Personal philosophy: show up consistently (reinforced by a 1,000-miles/year running goal)
- 2:31 – 3:02
Why “best-of-breed” stacks still get breached: hidden gaps between tools
Damien describes the operator pain he saw: companies buy top-tier security products yet still get compromised. Point solutions don’t capture cross-layer context, so attackers slip through the seams.
- •Organizations own “Ferrari-level” tools but remain vulnerable
- •Breaches often happen between layers, not inside a single tool’s scope
- •Solving compromise requires rethinking security from first principles
- •This insight became a primary motivator for founding Nebulock
- 3:02 – 4:02
Attack automation thesis: tailored access operations powered by AI
He lays out a thesis that adversaries will automate the full lifecycle of targeting and compromise using AI. Nebulock’s mission is to democratize high-leverage security work across org sizes and budgets.
- •AI will automate targeting → compromise → objective → stealthy exit
- •Goal: democratize elite security leverage regardless of headcount or budget
- •Approach: integrate with existing systems rather than replace everything
- •AI boosts both sides, but it especially lowers the barrier for attackers
- 4:02 – 5:33
The talent gap collapses into a subscription—and scales from individuals to nations
Damien argues AI compresses expertise: capabilities once limited to elite teams become accessible via tools. This cascades from individuals to companies to nation-states, and raises the prospect of “citizen hackers” unconstrained by rules.
- •Mythos-like models bring advanced capability to non-experts (“script kiddies”)
- •Security judgment still takes years, but AI narrows the practical gap
- •Adoption cascade: individual → company → nation-state (e.g., Cyber Command)
- •Citizen hackers are especially concerning because they’re not bound by geopolitics
- 5:33 – 7:07
Founder conviction: quitting with no salary and passing the “$0 test”
Damien explains the moment he quit his job to pursue Nebulock full-time. He stresses that founders must love the problem, validate with the market, and sustain conviction regardless of external noise.
- •Key self-check: “Could I solve this even if I made $0?”
- •Founder focus: obsession with the problem, not attachment to a specific solution
- •Early discovery validated the thesis and enabled the product to take shape
- •Conviction + evidence-building is essential amid uncertainty
- 7:07 – 8:38
How one person can hack an org today: blending into normal behavior
He walks through how attackers compromise everyday accounts—starting with Google Workspace—and move deeper while appearing legitimate. The hardest compromises look “green” in isolation and only reveal themselves in context.
- •Common entry: remote access to Google Workspace → Drive → endpoints → cloud resources
- •Modern attackers blend in (normal hours, valid credentials) to avoid detection
- •Key challenge: distinguishing real user behavior from compromised-account behavior
- •One patient individual can orchestrate much of this without a large team
- 8:38 – 10:40
The cyber kill chain and the cost curve: what AI already automates
Damien maps AI’s impact across reconnaissance through objectives, showing where automation is already cheap and where humans still matter. The strategic question becomes whether defenders can match attacker machine-speed.
- •Kill chain framing: recon, targeting, exploitation, persistence, lateral movement, action on objectives
- •AI has largely automated the first components (recon/phishing/exploitation/persistence trending cheaper)
- •Lateral movement and objectives still often need humans (for now)
- •Defenders have an opportunity to move to machine-speed too
- 10:40 – 11:10
From reactive alerts to proactive threat hunting: “assume breach” mindset
He contrasts reactive security (alerts) with proactive threat hunting, using the smoke detector vs fire marshal analogy. The goal is to find risk and attacker behavior before it becomes a persistent breach.
- •Attackers stay ahead when defenders only react to alerts
- •Endpoint-only or network-only views miss the enterprise-wide story
- •Threat hunting assumes an attacker is already present and looks for evidence
- •Nebulock’s origin: closing the proactive gap with cross-tool context
- 11:10 – 13:41
Three indicators of compromise—and why founders should fear inaction
Damien lists three practical signs an attacker is inside: steady exfiltration, out-of-role access, and persistence mechanisms. He argues AI shouldn’t be feared as doom; what’s dangerous is ignoring the warning signs and failing to act, especially given the current window to prepare.
- •Indicator 1: slow, consistent exfiltration that resembles normal backup behavior
- •Indicator 2: access outside role scope (e.g., intern viewing financials)
- •Indicator 3: persistence (RMM tools, new accounts/service accounts)
- •Message: don’t fear AI—fear inaction; Nebulock focuses on contextual signals across layers
- 13:41 – 14:53
What founders need personally: support networks and staying human
He closes on the human side of building a company: founders need support beyond the business persona. Damien highlights the importance of mentorship and being true to oneself while leading a team.
- •Founders must manage “you the CEO” vs “you the person”
- •A personal support network is critical to resilience
- •Damien’s dad as a mentor: deep understanding plus grounded guidance
- •Leadership goal: create an environment where people can thrive and grow
