ZeroSum
Aaron Mog
0
ZeroSum is a cybersecurity podcast that discusses the state of the industry honestly, rejecting typical threat-of-the-week news. It uses game theory to examine how the cyber market often leaves practitioners losing while VC gambles win. The show features guests from various perspectives, including vendors, investors, workers, and CISOs.
Episodes
-
We Don't Need to Throw Out Security, We Need to Update It. - with Diana Kelley 14.07.2026 1h"We don't need to throw out what we've been doing all of our careers. We just need to be AI-aware in how we apply it."Diana Kelley — CISO at Noma Security, formerly CISO at Protect AI, and a 25+ year veteran of Microsoft, IBM, and Symantec — joins Aaron for a grounded conversation on what actually changes, and what doesn't, when AI enters security.We cover why trust boundaries and identity are still the job even as AI reshapes the attack surface, why the LLM itself can't function as a trust boundary, the shadow AI sprawl most CISOs haven't gotten a handle on, and the identity mess created by agents inheriting permissions from whoever spins them up. Plus: does AI actually level the playing field for builders, or just make the biggest players bigger?Guest: Diana Kelley, CISO at Noma Security.⏱️ CHAPTERS00:00 Intro01:34 Nearly four decades in security — where are we right now13:23 The labs stole the data to begin with22:19 Shadow AI sprawl and the identity problem28:21 First principles: trust boundaries, not a full rewrite39:18 Are the frontier labs going to crush every startup?42:52 AI, equality, and who gets left behind55:56 Where to find Diana and get involved#cybersecurity #CISO #AI #infosec
-
Is Anybody Safe? Adaptability in the Age of AI Disruption - with Mark Carney 07.07.2026 1hIs any security company safe from AI disruption? Evolve Security CEO Mark Carney's answer: no and that's the wrong question anyway.Aaron talks with Mark Carney, CEO of Evolve Security and one of the OG figures in security services, about where the industry sits at a genuine inflection point. Mark breaks down why tech-enabled services are hotter than ever while human-only services are a dying breed, and how private equity now runs "AI disruption due diligence" before writing big checks.We get into:Why finding vulnerabilities became a commodity — and where the real value lives nowWhy Evolve deliberately isn't using AI for autonomous exploitation yetThe 50% false-positive problem with autonomous pen testing toolsAttack chains, business logic, and prioritizing high-impact exposuresChartering an "autonomous enterprise" across every business functionThe death of tasteful outbound and the abuse of the CISO relationshipCareer advice for a tough market: deliver outcomes, not activityGuest: Mark Carney, CEO of Evolve Security. Find him at evolvesecurity.com or on LinkedIn.
-
The Scariest Story a CISO Has Ever Told the Board - with Jason Loomis 07.07.2026 58m"This is the scariest story I've ever had to tell my board."CISO Jason Loomis on what AI is really doing to security teams.Aaron sits down with Jason Loomis for a raw, funny, unfiltered conversation about AI's impact on security teams, careers, and the humans caught in the middle. Jason lays out his "farm team" problem: the tier-one SOC, GRC, and help desk roles that grow new talent are being automated away and he's brutally honest with his own team about it.We get into:Why the security fundamentals haven't changed in 20 years, even as velocity explodesThe hype gap between vendor promises and enterprise realityVulnerability chaining in the era of frontier modelsWhy AppSec is the problem actually worth solvingThe build-vs-buy debate for security toolingA myth-busting rant on AI data paranoia and security theaterWhy "security is a revenue generator" is a line CISOs need to stop repeatingGuest: Jason Loomis, CISO at Freshworks and co-host of the new "Gen and Tonic" podcast. Find him on LinkedIn (no pitch-slapping, please).
-
The Cyber Industry Is Moving Fast but Chasing the Wrong Things - with Cris Neckar 07.07.2026 59mThe cyber industry is moving faster than ever and Cris Neckar thinks it's chasing the wrong things.In the debut episode of Zero Sum, host Aaron Mog sits down with Cris Neckar, security researcher turned entrepreneur turned VC at Two Bears Capital in Whitefish, Montana. Cris traces his unusual path from hardcore offensive work to venture capital, and explains why the biggest roadblocks in security aren't technical but structural: broken incentives, revenue-first boards, and founders who fall in love with cool tech instead of customer problems.We get into:The "scientist vs. salesman" failure mode that kills early-stage security startupsWhy Cris's first diligence question is always "let me talk to your customers"How the Cursor playbook rewrote the rules of company-buildingHow elite hackers use AI as a force-multiplier, not a replacementWhy "nobody wants to buy more red on a dashboard"FinOps for AI spend, compliance-as-collateral, and betting on power and data centersGuest: Cris Neckar, Partner at Two Bears Capital. Connect on LinkedIn or pitch via the Two Bears website.Cris is a Partner at Two Bear Capital. The views he expresses are his own and do not necessarily reflect the views of TBC or its partners.
-
Breaking In, Standing Out, and Becoming a "Data Shepherd" — with Wade Wells 07.07.2026 53mEntry-level security jobs are vanishing so how does anyone break in now? Detection engineer and educator Wade Wells has thoughts.Detection engineer, educator, and B-Sides San Diego organizer Wade Wells joins Aaron for a practical, honest look at entering and surviving in security today. Wade, who teaches cybersecurity students across all levels, admits the field moves so fast he can no longer confidently tell students what to do, since even the old advice can now be faked with AI.We get into:Why networking and a genuine community footprint beat a perfect résuméThe collapse of entry-level roles and the patience the job market now demandsThe "AI slop" problem: people submitting work they never readWhy everyone is becoming a developer — or a "data shepherd" who validates what AI buildsThe reckless reality of businesses uploading confidential data to AIThe coming "AI living off the land" attack and the yes-but approach to securityGuest: Wade Wells, detection engineer and B-Sides San Diego organizer. Catch him at DEFCON or on LinkedIn and Twitter — just mention where you found him.
Popular in
The podcast also appears in the podcast charts of these countries.