218 episodes
- In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading.
Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, backing hardcore technology companies across AI infrastructure, cybersecurity, and physical AI. He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched. He is also early in companies like Keycard, Surf AI, and June. About a third of Boldstart's investments are in cyber, so Ed sees this market from the founder and investor side in a way most security conversations do not.
We get into why the era of building raw intelligence is giving way to an era of controlling it, what that means for on-prem models and private evals, and why Ed thinks nearly everything in security is going to get rebuilt from scratch.
In this episode:
- Why a day-one partnership looks different now that anyone can vibe code an MVP
- The Protect AI acquisition and what the first exit in AI security signaled to the market
- Competing as an inception fund against mega-funds writing giant seed rounds
- What founders should actually look for in a venture partner beyond the check
- The shift from building intelligence to controlling it, including routing, post-training, and on-prem deployment
- Why enterprise data, workflows, and private evals are becoming the crown jewels
- Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation
- Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins
- The Surf AI thesis on automated security hygiene and tying every asset back to an owner
- The real bottleneck slowing agent adoption in the enterprise
Chapters:
0:00 Intro
0:35 Ed's background and inception investing
1:57 Day-one partnerships in the vibe-coding era
3:53 The Protect AI exit to Palo Alto
6:14 Competing as an inception fund against mega-funds
9:17 What founders should look for in a VC partner
11:48 From building intelligence to controlling it
15:52 Boldstart's domain-specific model portfolio
16:16 Private evals, context, and memory as crown jewels
17:18 Mythos, vulnerability chaining, and attack path reasoning
20:59 How much access should you give the model
22:07 On-prem context and the autonomous workforce
24:49 Agentic identity and Keycard
28:11 Building brand and community with Insecure Agents
31:30 The Surf AI thesis and automated security hygiene
34:13 The real bottleneck to agent adoption
37:09 The easy button, Palantir, and a multi-model world
38:24 Two types of people in this new era
Connect with Ed:
LinkedIn: https://www.linkedin.com/in/edsim/
Boldstart Ventures: https://boldstart.vc
Ed's newsletter, What's Hot in Enterprise IT/VC: https://www.whatshotit.vc
More from Resilient Cyber:
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
#aisecurity #agenticai #cybersecurity #venturecapital #appsec - Does restricting frontier AI in the name of safety actually make us less secure? Joshua Saxe joins me to make the case that it does, and that AI cybersecurity will be won through defender adoption, not restriction.
Josh has spent 15 years at the intersection of AI and security. He built and ran the machine learning program at Sophos, then led security for Llama at Meta, covering security post training, evals, agent guardrails, and prompt injection prevention. He recently left to co-found a startup reimagining vulnerability and exposure management agentically. He also writes one of the most cited blogs on AI and cyber policy.
In this episode:
- Why restricting frontier model access harms defenders more than attackers
- How monitored closed models put threat actors at a structural disadvantage
- The jagged frontier, and why attackers don't need frontier models for most of their tradecraft
- The national security and supply chain risks of pushing the world onto Chinese open weights models
- Why exploits don't cause cyberattacks, and which attacker constituencies AI actually unblocks
- The dual use ceiling on guardrails and classifiers
- Where defenders should be adopting AI right now, from access management to SOC automation
- Using agents to burn down the mountain of security technical debt
Chapters:
0:00 Intro
0:42 Josh's background, from blackhat teen to Llama security lead
3:07 The case for diffusion over restriction
6:14 Why restriction hurts defenders more than attackers
10:19 The jagged frontier and what attackers actually use models for
12:49 National security and the supply chain risk of Chinese open weights
16:08 Exploits don't cause cyberattacks
20:20 Where defenders should adopt AI right now
24:20 Guardrails, classifiers, and the dual use problem
27:34 Reimagining vulnerability management with agents
32:17 The structural advantage defenders hold
35:15 Policy wishes and the attacker's Claude Code moment
Follow Josh:
LinkedIn: https://www.linkedin.com/in/joshua-saxe-01845a1
Substack: https://joshuasaxe181906.substack.com
Follow Resilient Cyber:
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
#aisecurity #cybersecurity #vulnerabilitymanagement #aipolicy #opensourceai - Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat.
Sid is a Partner at Foundation Capital, where he invests at the seed and Series A stage with a focus on cybersecurity and IT infrastructure. This is our annual pre-Black Hat check-in, and a lot has moved since last year, from massive M&A to record-setting rounds in categories like the AI SOC.
In this episode:
- What has actually changed a year into the AI wave, and what hasn't
- Services-as-software, the $4.6 trillion market thesis, and automating cyber workflows across the SOC, IR, pen testing, and threat intel
- What AI means for cybersecurity jobs and how practitioners should adapt
- Consolidation vs. best-of-breed after Palo Alto's $25B CyberArk deal and Alphabet's $32B Wiz acquisition
- AI SOC valuations, including Seven AI's record Series A and Torq crossing a $1B valuation
- The double-edged sword of big raises and why founders should be cautious about the valuations they accept
- Why you can't simply spend your way to growth in cybersecurity
- Moats and defensibility when frontier labs can push into your category
- The Black Hat Innovator Investor Summit and the Startup Spotlight competition
Chapters:
0:00 Intro
0:52 What's changed a year into the AI wave
2:42 Services-as-software and the AI SOC
9:38 AI adoption and forward deployed engineers
10:57 M&A, platformization, and best-of-breed
14:17 IT and security convergence, plus AI SOC valuations
18:48 Seed-stage risk calculus vs. later-stage investors
21:43 The double-edged sword of big raises
26:20 Why you can't spend your way to growth
29:05 Moats and defensibility in the frontier-lab era
32:25 Deal flow, pricing, and staying disciplined
37:06 Black Hat Innovator Investor Summit
40:17 Startup Spotlight competition
43:28 Wrap-up
Black Hat is offering listeners $500 off registration with code USA500Resilient.
Connect with Sid:
LinkedIn: https://www.linkedin.com/in/siddhanttrivedi/
Foundation Capital: https://foundationcapital.com
Resilient Cyber: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners, founders, and leaders. - JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.
Description
AppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once.
We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.
Key takeaways
Gecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.
The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.
Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.
Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.
Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.
Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.
MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.
Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.
Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.
The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.
Chapters
00:00 Meet JJ and Ryan
02:46 Why Gecko is an AI security engineer, not another scanner
05:07 The trend of agentic and headless security tools
05:53 Why business logic breaks traditional SAST
06:27 The no-auth endpoint example and context outside the code
09:06 Attackers think in graphs, defenders think in lists
11:02 Commoditized exploit dev and the internet as one bug bounty
13:55 Shift left and why MTTR is a broken metric
15:07 Eliminating entire classes of vulnerabilities
15:51 Recurrence rate and avoiding risky refactors
18:22 The Cal.com case study and open source going closed
20:48 Consolidation and the shiny object problem in security
22:40 Where AI-driven AppSec lands in two years
27:12 What it takes to trust an AI security engineer
28:57 Where to find Gecko and the Black Hat talk - Every headline wants you to believe AI has rewritten the rules of cybersecurity.
Eric Doerr, the Chief Product Officer at Tenable a Resilient Cyber Partner, is not so sure.
After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded.
The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that.
Why this conversation matters
Eric sits at a rare intersection, having lived the post-breach world of the SOC and now building the pre-breach world of exposure management. That vantage makes him a sharp guide to what AI actually shifts for defenders, from why cheaper discovery makes prioritization more valuable to how AI becomes its own attack surface once agents start touching your data. If you own vulnerability or exposure management and you are trying to spend your next dollar well, this conversation is a practical map of where the real risk lives and what to automate first.
Key takeaways
Attackers are ruthlessly economical. Eric calls bad actors the perfect capitalists, spending the least effort needed to hit their goal, which is why so many still get in through unpatched basics rather than anything AI-powered.
AI has not rewritten the offense-defense balance. The attacker only ever had to be right once, layered defense and zero trust still hold, and the real lever is accelerating your program with fewer human loops rather than lamenting the asymmetry.
Cheaper discovery makes context more valuable, not less. Reachability and exploitability mean most findings are not worth chasing, so as AI floods teams with more of them, telling the truly scary hundred from the theoretical ten thousand becomes the whole game.
Being too small to target is a strategy on borrowed time. As automation drives the cost of attacks toward zero, the quiet bet that adversaries will hit weaker neighbors stops paying off, and Eric would move off that mentality now.
Humans should not be the bottleneck on every fix. Getting the workflow and tooling right is most of the work, and the rest is the organizational willingness to let validated automation act, even when a business partner would feel better with a human in the loop.
AI is special and not special at the same time. It is mostly just another attack surface, and Eric estimates 80 to 90 percent of securing it maps to patterns the industry already learned during the move to cloud.
Shadow AI is the first surprise in almost every environment. When teams scan the endpoints they already interrogate for AI artifacts, nearly all of them find something they never sanctioned, which is why discovery has to come before control.
The real AI risk is interconnection. A misconfigured database was a needle in a haystack until you wire it to an agent, and then a harmless question about the budget quietly returns data the asker should never see.
Most breaches are not even CVEs. Citing the Verizon DBIR, Eric notes roughly two-thirds of breaches trace to misconfigurations, and since about a third of Tenable’s findings are non-CVE, a third of your findings can carry two-thirds of your risk.
Agentic automation is finally killing the toil. Early users are automating drudgery like asset tagging and full remediation workflows, with one manufacturing customer letting automation handle 80 to 90 percent and scheduling the rest for change windows with a human notified.
Notable quotes
“Bad actors are the most perfect representation of capitalism”Eric Doerr, on why attackers do the least work necessary and often skip AI entirely.
“a third of their findings are two-thirds of their risk”Eric Doerr, on why misconfigurations, not CVEs, drive most breaches.
“you’re on the wrong side of history”Eric Doerr, on insisting a human eyeball every automated fix.
More Technology podcasts
Trending Technology podcasts
About Resilient Cyber
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Podcast websiteListen to Resilient Cyber, The AI Daily Brief: Artificial Intelligence News and Analysis and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Resilient Cyber
Scan code,
download the app,
start listening.
download the app,
start listening.
Resilient Cyber: Podcasts in Family
























