EVERY SPOKEN WORD
10 min read · 2,448 words- 0:00 – 1:09
Intro
- DLDamien Lewke
Mythos changes the balance of power in cyber. Two people in a GPU who, with enough conviction, can target a company. And I think that that will happen. But I also think, like, Mythos to me is not, like, existentially scary. Mythos is what we in security have been saying for years. Really, the question we should be asking is, okay, after Mythos, what's coming after? What are we ready for? We have a very unique window of time right now where we understand what is coming, and we have the ability to adopt technology. The question is, can defenders adjust as quickly as the attackers can? I'm Damien Lewke. I'm the founder and CEO of Nebulock. Nebulock is a contextual security platform. Really what we do is look at all the existing security tools that you have, and we find potential threats hidden between the layers. We raised the $25M Series A led by FirstMark with participation from all of our existing investors, so Bain Capital Ventures, Decibel, Zeta Venture Partners, and Step Function. [gentle music]
- 1:09 – 3:30
Love the Problem, Not the Solution
- DLDamien Lewke
I'm very fortunate I discovered my passion my first day on the job as an intern at a company called Northrop Grumman. So I started my career in the DoD building out cyber ops and threat hunting teams before being a relatively early, uh, employee at CrowdStrike, joining after the Series C, being there through and after the IPO. My first job when I was in the DoD, I actually worked full-time and went to grad school at night to get a master's in aerospace systems engineering. What that taught me was not to be a hero every single day, but what was most important was that you showed up and did your best as best you could day in, day out. That's really expanded as I've gone throughout my career. So on the personal side, I have a challenge where I run 1,000 miles a year. It's the same kind of idea, which is like at 10:30 in the morning on a Tuesday in February, can you show up and do your best the same way that you would on a Friday morning when everything is going great? I then had a chance to experience network security at Palo Alto Networks and, and managed detection and response running the AI detection security research product teams at Arctic Wolf, and I, I took a stint at MIT writing a graduate dissertation out of the computer science and AI lab there. What led me to start Nebulock really was a two-sided problem. So the first is beginning as an operator, I saw the real problem that all of our existing customers had at Arctic Wolf, and also what our 1,200-person security operations center had. The dissonance was everybody had already invested in these best-of-breed tools, and despite owning the Audi or Ferrari of security, everybody was still getting compromised, and it was because different point solutions to specific problems were not the way to solve how to get breached. It was rethinking everything from first principles. Two years ago, my thesis was adversaries, so bad actors, are going to use AI to automate tailored access operations. They're going to be able to automate the entire life cycle of targeting an enterprise, compromising it, achieving their objective, and slipping out undetected. And it was those two problems that led me to build Nebulock, the idea being
- 3:30 – 5:30
How the Security Talent Gap Collapsed into a Subscription
- DLDamien Lewke
we can democratize the most high-leverage activity in security to all organizations, regardless of size, skill set, or budget in a way that's flexible and integrates with the existing systems that they have. I'd say the power distribution has already happened. Much like how AI has enabled productivity for developers, it's also allowed both attackers and defenders to uplevel themselves. Elite AI engineering or elite security judgment, certainly elite security judgment, that gut instinct takes a decade or more to build, and that is a very small subset of people. But a Mythos allow a script kiddie, so a non-sophisticated threat actor, to be able to do things that used to be reserved to a very elite group of people. What the actual power convergence means is not, "Hey, can I do things faster?" But rather the talent gap has collapsed to a subscription model. It impacts it in a cascading series of events. So it starts with the individual and then onto companies because an individual can quickly adopt AI. A company can adopt AI relatively quickly, but ultimately this will go towards nation-states. And we see that nation-states already, US Cyber Command is using AI as a part of its components. That is really, really concerning. But I also think, like, the broader, more existential question is what happens when the citizen hacker, when one person gets access to a Mythos-level model? Because they aren't governed by geopolitics and rules of engagement. They can do what they want, and I think that that will happen. The number of potential threat actors is dramatically increasing. You know, you've gone from a few score highly sophisticated groups to honestly two people in a GPU who, with enough conviction, can target a company. You see earlier stage companies being targeted. We've seen this in the headlines recently where growth stage companies like Vercel have had breaches.
- 5:30 – 7:02
Quitting with No salary: The $0 Test
- DLDamien Lewke
That's no fault of anyone's, but just when more people can do these things, you're going to see a greater indication and a, and a greater veracity of threats. I got to a point in early 2024 where I decided to quit my job outright and focus on this problem. There was a core moment where I genuinely asked myself, "Could I try and solve this problem and make $0 doing it?" And the answer was a resounding yes, and it was at that point that I knew. I was ready. Thankfully, we've been able to grow and scale as a business. I'm joined by some amazing folks. We get to partner with organizations from the Fortune 500 to growth stage security companies like Cribl as customers. Why was I okay making $0 and going after this? As a founder, I think what you really need to be obsessed with is the problem, not the solution. Ultimately, you build a team to help you design the solution, and you validate your idea with the market to design the solution, but, like, you have to fall in love with the problem. And to me, the problem was just so pervasive, I realized, like, I had to do my absolute best. And you just gotta show up day in, day out and see, like, "Hey, wait a minute, is this something you can really go after?" And I was fortunate that I did early market discovery that validated the thesis and ultimately allowed us to build what we've built today. No matter how right or wrong the world tells you that you are about the idea you're pursuing, as an entrepreneur, the key is that you have conviction and that you continue to back yourself up with that. I think that's really important as a founder.
- 7:02 – 8:30
How One Person Actually Hacks with AI
- DLDamien Lewke
So do I think that cyber attackers are not just targeting governments or the Fortune 100, but normal people? Absolutely. They're able to remotely access your Google Workspace account. Once they have access to your Google Workspace account, they're able to access elements of your Google Drive, and eventually are able to find a way to work their way onto your endpoint system. Once they're in your endpoint system, they can basically go wherever they want. They can move laterally and access critical cloud resources because, again, they look completely normal. Those are the hardest to spot because those are the ones who in isolation have green flag activity, but it's only when you take a step back, you look at the sequence of events and the context of their actions that you can actually spot a glaring red flag. Whereas about 10 years ago, cyber attackers behaved in bad ways. I think that's what's changed a lot, especially since I started in security, right? Attackers are going to try and blend in. They're gonna log in at normal hours. They're going to steal your username and password so it doesn't look suspicious or malicious. Can I distinguish what Damien as Damien versus Damien whose account has been compromised, like, what that actually sequence, what that actual sequence of behavior looks like? And based on that sequence,
- 8:30 – 9:55
6 Steps of Cyber Attack
- DLDamien Lewke
can I say, "Oh, that's Damien. It's totally cool," or, "Hey, wait a minute, Damien's doing something he shouldn't be. He's been compromised"? The real concern here is everything I described is being done by one person, so you don't need a team to do all of these things anymore. You can do it as one very patient person. So if I could draw an axis across the cyber kill chain, reconnaissance, targeting, exploitation, persistence, lateral movement, and then action on objectives, AI has already automated kind of the first three core components and humans are being orchestrated on the last part. And then if I had, like, a cost on my Y axis, like, the cost would be very low and then it would get very high. So you'd kind of have, like, kill chain on your X axis, cost on your Y axis. If I were a threat actor right now, reconnaissance, basically $0. Writing a phishing email, also very cheap. Vulnerability exploitation is getting significantly cheaper. Establishing persistence is also relatively cheap. Right now, lateral movement and ultimately, like, achieving your objective still requires a human. It's a bit more expensive. A human plus an agent can get there together, but you still need a human. But the first four components of that is basically automated. As attackers go to machine speed, do we think that defenders are going to machine speed as well? I think we have the opportunity
- 9:55 – 11:30
Assume You're Already Hacked
- DLDamien Lewke
to do that now. The core thread that I saw was that as defenders, we're always one step behind the attackers. In the DoD, we had to operate with the information that we had access to without knowing everything the adversary could. At CrowdStrike, we scaled that effectively on the endpoint, but the endpoint was only part of the enterprise puzzle. The same at Palo Alto Networks, right? We had the network, but that was only part of the puzzle. And then finally, from the managed detection and response side at Arctic Wolf, you had best of breed solutions, but you could only solve problems as best as the existing tools that you had, and you're responding to everything reactively. So the common thread was attackers were always one step ahead of defenders, and that's because we were always reacting to alerts as opposed to proactively leaning into how threat actors might be getting around our systems. And it was that gap that prompted me to start Nebulock. That's really where threat hunting comes in. Threat hunting is analogous to cybersecurity operations, much like the difference between a fire marshal and a smoke detector. So in cybersecurity, when you have an alert system, that's your smoke detector. There's a fire going off, and I'm alerting you that something bad has happened. Whereas a threat hunter is like a fire marshal. They go into a building before the fire and they point out the risks or risk areas that might be impacted should there be a fire. Threat hunting exists under the auspice that you should assume breach, you should assume that an attacker is within your environment. So
- 11:30 – 13:00
The Three Signs an Attacker is Already Inside Your Environment
- DLDamien Lewke
does this specific person with these specific permissions have access to the kind of data they're touching? For example, there are really three key things that an attacker will do that show compromise. The first is there will be a slow but consistent exfiltration of data that looks much like backup behavior, all desktop files being uploaded to a personal Google Drive. The second piece will be performing outside the scope of their initial role, so the marketing intern accessing financial information. And then the third is at some point you will see some sort of persistence mechanism. That could be a remote management tool. being installed so that they can access the system from any time, or that might be the multiplication of accounts that they have access to. So opening up service accounts when they're a human user, for example. Those are the, the three things. That's exactly why we exist, right? Like, Nebulock is a contextual security platform. Really what we do is look at all the existing security tools that you have, and we find potential threats hidden between the layers. Cybersecurity very quickly is becoming like an existential question, which is not, hey, will something bad happen? But when something bad happens, what do we do about it? The key that we all have to accept is at some point, a threat actor will target us. That's not to fearmonger. It's
- 13:00 – 13:51
Don't Fear AI, Fear Inaction
- DLDamien Lewke
just the reality of a world where the democratization of cyberattacks is a reality. I would not fear that AI is going to catastrophically destroy everything when it comes to security, but rather that AI is here both to create and solve the challenge for network defenders. So the sky is not falling. What I would tell them to fear or be concerned about is inaction, that we don't see these warning signs and instead do nothing. So I think we have, again, like a very rare window to act, and that whole thesis, that whole idea is exactly why Nebulock exists, to democratize the highest leverage thing, which is all about finding bad activity before it becomes like a persistent breach and giving that
- 13:51 – 14:52
What You Need as a Founder
- DLDamien Lewke
back to the people. Now, I think one thing that as a founder most people don't think about is there's you, the business person, and then there's you, the person. Having a personal support network is really, really important. I think what makes my dad so great as a mentor to me is he understands me deeply. He's my dad. I'm very fortunate in that regard to have access to someone who I have a, a longstanding and deep and meaningful relationship with, and he also reminds me to show up as like my truest self as opposed to hyper-optimizing to be like just Damien the CEO, but rather like Damien the person, Damien the founder, Damien who wants to build an environment where people can thrive and grow and do their best work. So I was not anticipating that question, and it got me a little emotional. [sniffs] [gentle music]
Episode duration: 14:53
Install uListen for AI-powered chat & search across the full episode — Get Full Transcript
Transcript of episode 90UkODFm5P8
