Security Money: The Index Explodes, as the History of AI Teaches Us About Investments - John Willis - BSW #464
About this episode
Security Weekly Podcast Network (Audio) is made possible by:
AI is all the hype, but we're currently stuck at the bottom of the 'J' curve. Wild enthusiasm has given way to the reality of costs, benefits, and risks. What's next for AI and companies looking to capitalize on the AI trends?
John Willis, author, researcher, and technology industry veteran, joins Business Security Weekly to discuss AI's impact on fundraising. John explores what the history of AI can teach us about the current moment, including how to separate genuine technological transformation from hype and better understand where AI may take us next.
Next, it’s time for Security Money. The Index is exploding upwards as the markets continue to climb. Both the Index and the NASDAQ, hit all time highs. The Business Security Weekly crew breaks down funding, acquisitions, and performance of both the public and private markets.
The Security Weekly 24 Index is made up of the following pure play public security companies:
SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc
Visit https://www.securityweekly.com/bsw for all the latest episodes!
Show Notes: https://securityweekly.com/bsw-464
Get every episode summarized
Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Transcript ready
691 searchable segments. Every word is indexed and playable.
Full transcript
Security Weekly Podcast Network (Audio) — Security Money: The Index Explodes, as the History of AI Teaches Us About Investments - John Willis - BSW #464. Machine-transcribed; use the interactive transcript above to jump the player to any line.
This week, it's time for security money. The index is exploding upwards as the markets continue to climb, both the index and the NASDAQ at all time highs last quarter. But first, we welcome John Willis, author, researcher, and technology industry veteran, to discuss AI's impact on fundraising. Business security weekly starts. Now, it's the show where we explore the business of security to improve the security of business. More trusted source for emerging risks, leadership, and communication. Get ready for business security weekly. Welcome to Business Security Weekly. This is episode number 464, recorded August 31, 2026, but will air on September 7, 2026 for Labor Day. I'm your host Matt Alderman. Joining remotely are my co-host, first Mr. Jason Elbacurky. Welcome Jason. Matt, how goes? Hands you're back in school, time for a little bit of structure in the Albacurky House. Listen, I'm good with that.
You know, summer chaos. I mean, summer is too soon. It is what it is, but at least we're back to some structure. And back to the NFL season here in a little while, right? Nine. For skin, Patriots, let's go. Yeah. So Jason, this is the one thing I've taken away from the preseason. The Browns third string offense is better than the Patriots third string defense. That's all I got. Absolutely. I can't wait for our starters to play each other and we bury you. Yes, you will. It's okay. That's all that matters, right? Guys, I got to tell my I grew up a Jets fan. And the reason I'm a college football fan and don't watch the NFL is because I grew up a Jets fan. Because you grew up a Jets fan. John, I have the same problem being a Browns fan, okay? No, no, no, no, no, nobody's worse than the Jets. John, did you call it James? No, guys, the Jets have gone to a Super Bowl. Wow. Yeah, well, that's why that's my curse. It's, yeah, I was nine years old when that happened.
Yeah. My Browns have gone zero times, folks. There are zero big goose. Summer, it's Auburn. Auburn. Oh, I'm so sorry. I'm going to see. I'm a Tennessee fan. My daughter's at Tennessee. Oh, yeah. We're going to go to that game, I think. Yeah. Oh, yeah. Great. Yeah. So that would be fun. Also joining is Miss Summer Fowler. Hopefully you were in that Pittsburgh youth football fight the other day. No, no, that would have been really amazing to have been in that. I get enough of that hockey with the parents. Usually the moms, by the way. But I wasn't at, I was at the Steelers Stadium this weekend for the Bruno Mars concert, which was amazing. So if you get a chance, go see Bruno Mars. He puts on a heck of a show. He's just, I mean, he can sing, he can dance, he can play every instrument. It's awesome. So great time. That's my son's second favorite, I think. Obviously Kelly Clarkson was like the hit for him, but I think Bruno Mars is pretty far
up there. So I might get sucked into one of those one of these days. We'll see. Oh, do it. All right. One quick announcement. Then we'll get into the interview. InfoSec World brings cybersecurity professionals together across industries from healthcare and financial services to government and the Fortune 500. Join the community in Orlando, October 12th to 14th for practical education, new perspectives and cybersecurity research unveiled live. Listener saved 30% on their pass with code ISW26-SW Savings by visiting securityweekly.com. Forward slash InfoSec World 2026. And that code is in the show notes because that's a mouthful. John Willis is an author, researcher and technology industry veteran with more than 40 years of experience, exploring how emerging technologies transform organizations and the people within them. He is the co-author of the best selling the DevOps handbook and is widely recognized when the foundational figures of the DevOps movement. His latest book Rebels of Reason, the long road from Aristotle to chat GPT and AI's heroes
who kept the faith tells the human story behind artificial intelligence. John, welcome to Business Security Weekly. Yeah, I'm in to be here, y'all. Yeah, yeah. So when I did the prep call for this interview, I wasn't quite sure which way we were going to go and then we started talking. We're like, we're doing our security money segment. I'm seeing all these acquisitions. We're seeing tremendous consolidation. And my hypothesis is the following. Companies can't get money anymore because AI has completely disrupted the Apple cart. And so what we're seeing is we're still seeing some fundraising for companies that I think have to kind of survive. But the ones that can't get money, they're getting acquired and we're going to continue to see this consolidation because AI is disrupting a lot of what's going on the fundraising side. What say you? Yeah, no, we had that conversation about this and even just what yesterday that IBM's buying confluence, which is the Kafka folks.
Next to the funny story, when I was at I sold a company to Docker and they bounced around because I was a Southern anomaly, I was the founder. And they finally put me in BD and at the time, this is the daughter of Docker, a rocket ship. The only people who are more arrogant than the Docker founders were the confluent people. You know, because they, everybody wanted conf at that point. But yeah, no, it's funny. I think that we're seeing almost like this stamp of when you start seeing the big organizations almost become private equity. I think there's a land graph for like what you said. But there's a lot of confusion on what's investible. It's a very difficult problem right now to figure out for anybody, certainly venture capitals. And I think even sort of the Google's just spraying money on just like what they do, but it's like pennies on the, not even fractions of pennies on the dollar, the money they're spending.
So now what you have then is like there's a land grab to grab the real estate of what's tangible, right? So you know, I don't know what that fits in. I know you focus on the security domain, right? But the conflates a good example of like they're looking at the spectrum. They know a lot of new stuff's coming out. Let's get anything that's near the top right now and just take it off the market. And I think it's a it's a prelude to I think we're going to see a lot of hiring brands, which aren't the monsters, not the Cisco's it, but you know, like I'll give you example, I would think somebody like Pagerduty probably would be up next. Or you know, like that, those are the kind of acquisitions you're going to see. And you know across the board. Is that because they want the client base more than they want the technology? I think it's actually both and that's that's a tough question to answer.
But I think it is actually both because I normally would fall in the like they're like count because conflates a good example is they don't I don't think they have a massive mass of client like they don't have a client base like somebody like Pagerduty. But they have a big enough, you know, sort of grab of the institutional, you know, like the institutions have Kafka, right? And most of the institutions of the years would want to go with somebody who supports it, not just an open source project, right? But like somebody like Pagerduty you'd go for this sort of the mass, right? So I think it's a little above, but I do I don't think it's exclusively, I think conflates a good example of of going after sort of a good enough base of enterprise customers, but securing that technology because they know it's going to be a piece of glue that's going to be critical for the modern data center, you know, which we see insanity, you know, proposals for that build out. Security teams are overwhelmed.
In 2025, more than 48,000 vulnerabilities were disclosed yet only a small fraction pose real risk. Most organizations remain stuck in a reactive cycle, responding to everything without the clarity to know what actually matters. Original, a global provider of independent software support is built on one principle, giving organizations control over their own IT roadmap, risk, and critical systems. Optus by original is a predictive intelligence service that brings that same approach to security, helping teams predict risk, validate what matters, and act with confidence. Visit securityweekly.com forward slash original for a conversation with a security expert today. John, John, quick question for you. How much is operational diligence playing a part in this? I mean, a couple years ago, we had Robert Hershvack on here. And he started talking about this trend. This trend of now investors are starting to look at the things I probably should have looked at for a long time, which is EBITDA and profit margin and financial diligence and
running a well-run company. Are we still in that? Believe me, Matt, you've seen it somewhere. You've seen it. It happened over the last couple of years where there was diligence happening on the financials of acquisitions. Are we still there? Are we shifting back to a kind of cowboy show again? I'm going to be a little cynical here. I think most organizations, once they get past certain state, become chaos. So I was a principle of somebody who saw the company at Dell. Right? And I will tell you, the operational diligence is just nonsense. I mean, I can't get into the glory details. But that was as big as you gave. Even though we were small potatoes, we went through the process. People, there was only eight of us that knew what was going on. And I remember I showed up in a suit and everybody was like, oh, we're getting sold. If John's wearing a suit, we're getting sold.
Yeah. Yeah. But yeah, I mean, so I mean, I don't. I've seen, we all have, but I've seen firsthand how sausages made at some of these companies that make good money that look great from the externals. And once you get inside, it's just so wonder that they actually can't get anything out the door. And you see organizations get purchased. So I'm not sure. So just sort of balanced the answer to that. It's probably true that there's less operational diligence going on in this world right now. But I would contend that, I mean, that's when, what was it? eBay bought, what? Oh, the eBay bought the original phone company. I'm flanking on it. And they did get the, yeah, no, it was, it was one of those. I was, yeah. Oh, those Yahoo, that's right.
Yeah, I'm sorry. But like, if I found that you don't go, oh, yeah, yeah. And they didn't buy the intellectual property. And they found that after the acquisition. You know, billion dollar acquisition. And nobody on the legal team secured the fact that when they bought the company, they didn't own the way they found that is the founders went back and tried to basically, you know, do a rebuild. And they got a cease and decision. They were like, no, actually, you know, you don't own this technology. So again, I'm pretty cynical for the biggest companies, you know, and I almost sold the company to IBM one time. And I don't buy that there is really, you know, I mean, just face it, y'all. Software companies are terrible at business. Yeah, they don't really have the structure of like retail or manufacturing. But from a funding perspective, there is a lot of diligence going on because I think the challenge right now is what's real
and what's not real, right? Can somebody rebuild this capability and completely bypass, right? So back in the day, right, I worked at both call us intenable. The thought process was, listen, nobody can catch us because we have all this intellectual property in all of our plugins or QIDs. We have this big vulnerability database. No one's ever going to rebuild all that and compete with us. And then Mithos comes out and starts finding vulnerabilities that they didn't have in their library, right? That's a pretty earth shattering kind of capability all of the sudden. I was like, whoa, what I thought was a moat is no longer a moat, right? And so trying to figure out your moats and whether they're safe or not, is really, really hard in this environment. And so if you don't have a really good handle, my opinion on where your true intellectual property and where your protections are, it's going to be really hard to get funded because
Chatchy PT just might go create it all for somebody else. Yeah, I think I could friend of mine. He was one of the first fellows of Capital One. He was on the team that invented the jar file. He said to me just recently that I'm sort of paraphrasing, but he said, if you've got a software company that's less than five years old, you're toast. I don't know that's necessary, but I will say that figuring out where the moat is is not just a technology. We all know that, right? Because I'll hear really smart people, the friends of mine will say, you know, I think somebody could rewrite Salesforce.com or they could write, you know? And like what you're discounting is 25 years of learning how to build channels and all that stuff. So there's a lot to an organization that isn't just a technology. So the hard part then, and again, the less than five, you don't have that heritage, right? In general, unless you have a very specific moat that you built around the technology or an early on something.
But in general, companies have been around 10, 15 years. They're more than just a technology. They've learned over the years how to deal with that software, particularly the enterprise space software companies. And so I think people look at, you know, sort of immaturally look at, like, well, I could rewrite Salesforce.com or I could, and I wish somebody would, but but what they're discounting is like all the other stuff that goes into a business like that, that is marketing, that is channel partnership. Just the general systems view of like what they do. And that you can't create with that GPD. I mean, there's another risk too. I mean, coming out of Black Hat this year, there's a lot of talk about code slot, right? So you have these companies who are a couple years old, they're writing everything with AI. Yeah. And it's this paradox of efficiency, right? They're getting efficiency because they don't have to hire as many software developers, because they're leveraging AI to build it. But they're finding that the code is garbage underneath.
It's not create code underneath. And it has a lot of bugs. It has a lot of vulnerability. And so many researchers were talking about the amount of slots that's out there. And unless you're doing your diligence, if you're looking at acquiring a company, unless you're doing the diligence at that level, you could be taking on that risk. That's right. It's on a tech debt. Yeah, and there's a lot of risk right now. And so somebody, just one more point, because I use an interesting point too. There's two ways to look at that, you know, the code slot. Well, first off, the dependency map has been the sloppiest thing, you know, before AI started generating code, right? Like in other words, it's a nightmare that is just tangled up in libraries of a library. You know what I mean? I write 10 lines of code. It turns out to be like 10,000 lines of code, right? Because I don't write really anything. They're all dependent libraries, right? And so that's fine. So that that monster is out there, right? And so AI is just creating more of that.
But another thing that AI is doing, a good friend of mine has a startup that looks at like context-based security analysis. And what they're finding is that when you're using AI, a lot of times it's rewriting libraries. So even though the dependent library is so terrible or in general terrible, a lot of stuff has been vetted out for 10 years. So there's like, you know, a stretch too, which is a bad example, because people know it as the horrible thing. But that code has been run trillions of times in banks and insurance companies. And so AI looks at something like a parser and says, I could do that myself. Why would I use the library? So you're getting a lot of untested new code that, you know, in the overall, even though I complain about the dependency nightmare, the truth of matter is like a high percentage of it works and runs like every business on the planet, right? And that stuff is institutionalized. And so what AI is short-cutting a lot is stuff coming up more clever ways to build those.
So you're getting a lot of new code that has them in exposed, has no signatures. And, you know, and like is brought with like terrible decisions that might. Yeah. Bugs, vulnerabilities, etc. If anything is proof, look at what just happened on August 17th with the GitHub outage. They've never seen so much code being put up in GitHub in history. Yeah, yeah. Think about why you think it's developers actually going out and do that? You think that's a lot of the AI slot that's going up in there? I mean, they got them already and they had an outage because of them. And the meta point though, and the meta point is that we never really be good at writing. You know, there's a panel going on this weekend and ACM conference and some friends of mine, right? They said, the top of this, can we trust software in my AI? And I said, that's a wrong question. Can you really trust software written by anybody? And the two of those, you can't, right? And so now we're just getting a lot more of it. So I'm sorry that I cut you off. No, no, that's great because that was an important point.
I actually have two questions for you. I'm going to start with this one. So, you know, you've been in the DevOps base for all these years. And when that was ongoing, part of the messaging there was, let's get humans out of these repetitive things, right? And now we're in this era where AI is actually helping to take humans out of the non-repetitive thinking things. So, where do you think, as you're advising, even thinking about these acquisitions, where do you want to see the human? Where do you find that like having the human in this part is the most important place for them to be? Yeah, I mean, to be honest, right? There is an industry learning curve here. The simple answer is we talk about human in the loop and human on the loop. So, we get to a gentics, right? We have to figure out more clever ways to be sort of on the loop. A good example might be like with a gentics, right? You know, like the whole point of an agent or an agent's base or swarm of agents is that it's
going to do a whole bunch of stuff in an automated fashion. The risk is, what is it going to do? So, one of the things that we're already starting seeing is, you know, like a simple automatic replay or a kill switch idea or an escalation policy, right? So, if it was the samples, I run some workshops on agentics and rogue agents. And, you know, one of the examples I use which is simple that you have an agent that's going to send out a proprietary or an intellectual property based email to the sea level team. You know, an escalation policy would be, there's more than 10 of them going out. Let me go throw that into Slack and get somebody to double check, right? So, start thinking about, and what's going to happen is what's going to get really fascinated is, what is audit going to look like? Internal audit going to look like in a couple years. And, you know, and we either start defining what it looks like or what the auditors are going to come back and ask the questions.
So, it's a, they're already asking the question, right? Well, I'm already getting questions about how do you validate the output of an AI agent? And how do you get ready for an audit for that? But, yes, so I mean, that's actually, and there's an easy answer for just a general inference question, right? And it's called evaluation software, right? So, the LM is a judge stuff, right? So, I mean, there, you know, long story short about five or six years ago, about six of us wrote a paper about what we defined called DevOps Automated Governance. And the idea was to create digitally signed at the stations, immutable as citations, so that like in order to do, like you don't have to have all this nonsense of spending six weeks a year having to say, well, the service now said this and you had this law. No, these are, you know, basically signed evidence that goes into an immutable structure that the answer is, hey, you know, like we don't believe our saying encryption, then like we got a much bigger problem, right? And so, what we're trying to think about is like,
how do you do that for, for this new sort of probabilistic world? And so, it is actually reasonable. But here's the thing, I don't think the orders have caught up on this. I don't think they actually understand evaluation software or LMAs of judge, but I can build into my pipeline of an inference pipeline, like where the data is coming, the rag, the embedding model. I can checkpoint all those and then I can run ground truth to do an adversarial check to say, am I getting a level of correctness that's accepted? Am I getting a level hallucination? Like, that's all mathematically and sound can be done. The problem comes into when you get into agents. You can't run with, so LMAs of judge works on like sentences and words and you should never give this answer or use this wrong word, you should use that word. But what you can't do is really build ground truth on what is good code or what is, and not to do good codes like the wrong
ways fabric, what is the right decision being made by the code? You know, in my workshop, I'll tell people, I want, you know, like, oh, I want everybody to write a 10 line, you know, and I'll usually say, let's use Python, a 10 line to solve this. And then like, you know, and literally you have, if there's 50 people in the workshop, you have 25, 30 different sets of code. Right? So that's the problem. That becomes like, what are orders? How are we going to show evidence to auditors that we did the due diligence to be able to have a system to be able to say, when an unknown, unknown, known becomes an unknown known, how do we circle that back in? And that's why I think early evidence is things like replay or escalation policies or, you know, some type of kill switch. Did you have a kill switch? Right? Like, why don't you even think before that, John, it becomes accountability. So before you even deployed that agent, who is accountable for the
actions of that agent, that's where it really gets real because all those other things can flow from that. Yeah, I mean, they account it's a great example. And even though it was, it was probably wasn't even gender very high, but the air candidate lawsuit, you know, I don't know if a lot of people know, it's, it made news for a couple, for about a full year. Basically, a young man was going back for his mother's funeral, didn't have a whole lot of money went into a chatbot on air Canada and said he would get a refund if he did. Calls back in air if he gets back, they say, oh, yeah, no, that's the chatbot. And he sued him. And the, the, the ironic thing is they probably lost a half a billion market cap over some period of time because they were on the front page of the Wall Street Journal as the poster child for when everybody's waiting to pound on AI, right? And the payout was less than a thousand dollars, right? Like, so don't be an air candidate, but here's the thing air candidate of me, the false assumption that they could blame AI, right? You, it has them to your point, ever. That's sort of one-on-one in my workshop or, or when you're thinking
about this, you got to have an ownership. Because you're not going to be able to say, well, you know, that was, you know, sort of AI made that decision. So therefore, you're, you know, you know, you're going to have to think the brunt of, you know, four million dollar transaction that shouldn't have happened, right? No, there's going to be a, it has to be an accountable organization. You can't sue an AI. You can't sue a chatbot, right? You know, the, you know, so yeah, no, you're spot on, and that is part of, then here's the thing, right? Is risk is completely broken. People are taking old frameworks and they're lay around and they're calling the new AI agent framework. And it's, it's completely different. It's probabilistic. It has brought with different types of problems of inference, worse inference of code. It, it has to have, you know, we have to understand what is the liability? It can't be an agent, right? And those are hard, these are hard problems. These are
not simple things to figure out. I couldn't agree with you more. I say this to my clients all the time that it's, it's the risk portion of this that is not well understood because it's great to take AI into your organization to use in the right way. But you have to remember, you're taking a non-deterministic system that is essentially a black box and it's going to give you something and because it's non-deterministic, you don't actually know what it is. Therefore, you have to determine the risk and put the right deterministic control around it. And that's hard. That's really hard to do it when you don't understand the risk fully. Well, and, and, you know, I was telling Matt this in a call we had earlier of that, you know, the, does the old risk equals likelihood times impact, right? And yeah, all right, so whatever. But, but now there is like, sort of an exponent of, of, authority. Because now you have a world, it's not just that it's inference base. It's that it's,
it's a machine, a machine spate, it be mechanism that has infinite knowledge. So when we see these things like, you know, some of the red teaming stuff that happened with anthropic with the, you know, the, I mean, it's kind of fun to read the, the, the, the system cards for, you know, the red teaming, but like, you know, the, the blackmail, but that was sort of, you know, sort of a, there was, you know, it was a game set up where they told it it could use black mail. But like, there was some other really interesting, you know, there was like what I call the Kobayashi Maru version where it literally, they gave it a benchmark search and the AI figured out that it was actually being benchmarked and went back, found the repository of the, the, the sort of context for that test and then answered the question the way it was supposed to be answered based on the author who created a test, right? Like that, that because you have infinite, I'm held, I'm sorry, I held the, the, the, the, the, the, the postmorm on the, the, hugging face.
Yeah, I was saying, I was 10,000 agents. Yeah. Yeah. I mean, without the right guardrails, you're giving these agents agency into your organization that had, and these agents have infinite knowledge and can do what every text win the game. But what they don't have, so they have infinite knowledge and I love that as a phrase, what they don't have that we've not done well enough is we haven't given them the context in rules of engagement, plus the, put the, put the work into the controls that you're discussing. That's right. We haven't infused values into the agent yet. That's the reason we can't, we can't, I mean, even just rules of engagement. Yeah, yeah, like, no, that's why I think authority is like it's an understated like the, and it's why I make it an exponential, right? Or in that, like, in other words, I need to think now if I'm creating an agent that has read authority only, you know, or is it going to have right authority? I need to like, I need to
come up with some type of control mechanism to think about because if I'm giving it right authority and the fact that I know that it is infinite knowledge, it misfein speed, and I can accept that it could come up with really clever ways to, to do what I think it wants to do. And, you know, I was telling Matt that, you know, there's been some really interesting stories that I've run into. I do these presentations on rogue agents and I just love like people come up to me and they say, oh, John, you want a really good rogue agent story. I'm like, yeah, yeah. And, you know, one of them was this, this young man was literally, basically it was, it was a sock to a PCI environment, right? And he, he was going to do something to remediate some servers and he figured, let me go on the Claude and Claude code and do it. And he gave it like, this is insane, but he was young. He gave it fire call. So he gave root access, right? And, and so, you know, but the thing was to put yourself in this young person's seat, he probably figured, well, obviously it would go to like the
F5 or go to some place to go get the list, right? No, it figured out much more efficient way to get the list of keys. It went to Vault. So it dumped all the Vault secrets into Anthropics Public Cloud. And for the next three days, he had to rotate skills when he was manageable. I was just back. He didn't get fired, but, but I mean, like we, we can't comprehend the kinds of decisions. But what we can do to your point, Summer, is we need to start thinking about blast radius and authority. And like, if I'm going to give it like one nanometer of authority, what is the blast radius of it? So that's why I say it sort of blows up the whole, you know, whatever anybody thought about risky goals, you know, like this time in book, it has to have now this new spectrum of authority. Authority. Yeah. And I think a new new new new new new new new new equation, you're going to have to name it. How do you pull guard rails around intent? It's intent and agency
that these things have, right? And I mean, you know, the hugging face, the post-mortem is key. It didn't have access to certain things. You know what it did? It required I know. I feel like AI agents are the middle kids of technology, because I feel like my middle kid will do fight. I think I need to do anything. That's funny. All right. Right. I get suns like that. I'm going to start calling him and he won't get it. But like if there's a will, there's a way my middle kid's going to find it. Yeah. No, that's something is, you know, the first question, you know, like the, you know, the sort of like I love having this conversation or the CIO, like, John. And then fortunately, there's less and less people saying this out loud. They all think it. But is, um, John, you know, for something like this, it can never, ever, ever do, you know, this. And like, well, then you can't use AI friend. You just can't, like, there is no such thing as a never, never
in this world. So, so then the question is, what is the calculated risk knowing that there is a risk? What do you do to, to, you know, in loose frames, guardrail, but it's way more to basically show evidence that you accepted. That's why I go back to the automated governance structure. You know, at design time, you need to have a conversation with internal risk and second line or whatever. And literally say, you know, there's a risk here. Okay. And you know, if the answer is no risk then no AI. Okay. What's the risk? Let's assume that it's 5%. And then like, okay, we all shake hands. We agree that there's a 5% risk of some grinding. And you know, depending on what it is, maybe 3% 2%. And then I can at least calibrate the inference through the evaluations and mark that as evidence that every time I change anything in the pipeline that is fed into the inference engine for this, that I've at least checked that it didn't go over that say 3% correctness or
3% hallucination. Again, that's not a hard problem per se. The hard problem is how do I calibrate risk for agents to make decisions about agents when there is no sandbox? Because it's 3% 3% 3% 3% 3% 3% 3% 3% right compounded. It's compounded. It's like compounding interest. Yep. Oh, what a great way to end this segment and brought up the money factor. Yeah. There we go. Yeah. Yeah. Yeah. Totally. Yeah. John, thank you so much for joining us. Yeah. Thanks for having me. I love it anytime. You're all this fun. Zero trust is clearly the future. It's threats get faster, quieter and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software are stopped cold. Trusted apps stay contained and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats
ahead. CYC's are adopting it at securityweekly.com for its last threat locker. The rules just changed. AI like mythos now finds and weaponizes zero days on its own. In your patch window, just drop from weeks to hours. One prompt to TANYM Atlas. It scans thousands of endpoints in seconds. It confirms which machines are actually breached, then hunts the attacker's command and control. Atlas then acts to isolate, quarantine, rotate credentials and patch every endpoint in real time. TANYM Atlas. AI that doesn't just answer. It executes find out more at securityweekly.com for its last TANYM. Now let's get into the security money segment. So I'm going to pre-empt the answer gas it's still 24. Is it still 24 Matt? It's still 24. No acquisitions, no IPOs. It has not moved. But I did have
to adjust for two stocks splits. Both Palo Alto Networks and CrowdStrike had stocks blitz. What happens with the, I use Google Finance to do all the calculations is it goes back and retrofits the share price post stock split. So there was a little bit of cleanup to do but nothing else really changed at all in the index itself. On Friday, the index closed at 5,038.63. It's a 403.86% increase since the inception, which was baseline at 1000, which is way up. When you see the charts, which I put into the show notes, you'll see that the index was way under the NASDAQ and it basically just caught it in this last quarter. It's about 300% gain. Yeah, it's crazy. Yeah. It also hit a record high of 5273.06 on August 13th. So not only did it go up,
it went up actually a little higher. It basically doubled. I think from the last time we did the show to it's all time high. Big time move. Big time move. Yeah. And I think a lot of it came down to CrowdStrike. CrowdStrike is heavily weighted in the index and it has doubled, basically doubled since the stock split. So it put a lot of extra points on the index this last quarter because the CrowdStrike stock just keeps exploding. Yeah. So do you think with it being CrowdStrike and so heavily weighted in what we're seeing? Do you think that there is any indication that we're seeing a maturity in corporate security budgets or do you just think that this, like the trend of what we're seeing in the numbers going up? Or do you think it's just really weighted because of CrowdStrike? No, but everything's kind of going up somewhere. Right? Like remember, we had some bottoms. We had
rapid seven at a bottom. They were like seven bucks a share. Right? They're up now. Right? They're up like around 12. So every stock is getting a little boost from this AI investment. And I think it's because people are trying to figure out, okay, I know I need to do something about security with AI. I still have questions about the longevity of some of these stocks. They're a bubble. Yeah. Are we looking at a bubble? Well, we saw it in the NASDAQ a little bit, right? Which we'll get into in a second, but we saw it, right? We saw kind of a pullback on the AI stocks and the data center stocks and this and the other thing. Well, that have the same effect on security stocks. And so I think there will be some reductions. And I don't think every stock is going to continue to see these increases. I think the market's still trying to figure itself out. Yeah. NASDAQ close at 2640242, which is an increase of 297.91%. So the index has now outperformed the
NASDAQ. It's down slightly from last quarter. Remember, it's pulled back a little bit. It did hit a record high of 2709390 on June 2nd. So the NASDAQ's definitely pulling back from its all-time high. So it's about a two-month delay, roughly. So let's see next quarter when we do this. Do we also see the index kind of coming down slightly down from where we are because it's a little delayed? Yeah. Maybe. Maybe. I mean, look, the index has tracked the NASDAQ pretty well. Over the eight years, we've been tracking this thing. And so as the NASDAQ pulls back, it's very possible. We'll see the index pull back, too. Yeah. Yeah. Let's see. Pulled the results quickly for Q1. So revenue beat by 2.98% on average. That's up from last quarter. Profit beat by 11.4% on average, which is also up from last quarter. So as I was doing the results, I'm like, wait, everybody beat? Everybody beat? No, not quite. So we did
have a couple misses, but there was a lot of beats pretty much across the board on the index. The worst performers, Rubric, checkpoint, and set in a one, they all had slight misses either on the revenue or on the profit sign. But Rubric show grew, right? I mean, I was looking that up. It Rubric's had their subscription ARR grew. Right. Yeah. I think they missed on top lane revenue. Got it. Okay. Right. Based on expectations. So it did have a negative in its performance. The best performing was fastly veronus. Yeah. It is. I mean, it's not about them being underperformer, right? Exactly. I know. And it's probably because expectations were dropped so much. Maybe. Right. After a while, you start going, okay, they're not hitting their numbers. So they start, they start, you know, putting different expectations in place. And then they outperform. Anyways, kind of crazy. Average analyst rating 1.767, moderate by, down slightly, Rubric's
Palo Alto and Zscaler are the best rated. Radware, Rapid7, again, and checkpoint are the worst rated. So this is where I think you're going to see some of these stocks start to struggle, right? Like Rapid7 did come back off of its bottoms. But is it going to stay there? Even checkpoint with some of its misses. Is it going to stay there? Right? So that's where I'm waiting to see what happens next quarter with some of this pullback. And they've been constants on our list here for a while. I know. I know. If you're in the world, right? Yeah. Yeah. Yeah, agreed. Let's see. Some interesting news for the public company. So Sentinel 1 laid off about 8% of its workforce. And they say it's due to restructuring and AI investment. But it wasn't viewed positively by people. Somebody said it was called, somebody said Sentinel done. Oh, man. No. Yeah. Exactly. I thought it was funny. And then
Akamai raised 2.6 billion in post IPO debt. Yeah. Yeah. That's crazy. You know why? Because they got to go build some AI capabilities. I bet you're right. Anything. They're going to catch up. Exactly. So this is one of the challenges, right? So if you're in the, if you're IPO, you're out there and you don't have a bunch of cash on hand. Now, I think Crowds are probably sitting on a bunch of cash because their stock price is going up so well. And I know they have positive net cash flow. It's hard to make investments in some of this space to make acquisitions other stuff. So what do you do? You raise some debt. And then you use that to make some strategic move. So I'm expecting Akamai to make some moves sooner than later with some of this additional investment. Do you think it's going to be, well, we should have asked our last guest to build her buy? Yeah. Well, that was a, that was a part of our conversation during the prep call. We talked about a little bit. Yeah. We didn't have time to
cover it on that last segment, but how many people are going to start building their own stuff? Yeah. Yeah. You know what I love to see? I like seeing post quantum in the equation and in the conversation. Yeah. Because the investment there on post quantum, I mean, I still think it's the the mega blind spot that businesses on focusing on or thinking about. And I mean, the goal post gets moving closer and closer. I mean, yeah, federal government saying 2030, but I've heard 2029. I heard a year and a half from now. I mean, have you heard of any, any investment right now? Have you heard of any AI companies that are focused on post quantum and helping companies to do? Because the big thing is going to be post quantum is not a one time and done. It's the fact that there's, there's full rotation all the time now. I haven't, I have not seen an AI company that's focused on that, which is interesting. There are, there are coming out of DEF CON, there were a couple of researchers out of colleges, out of universities. Okay. Actually building assessment tools that you can run on your environment and hold back all the cryptography within your organization, find all the blind spots and then give you the ability
to have this number one visibility into what's within your ecosystem. Then secondarily, what risk it presents. Yeah. I know IBM's doing some work on the services side around this, but I haven't not aware of any AI worker bot doing anything there yet, but maybe. It's an interesting question. Yeah. Yeah. I said, yeah. And I say to myself, if you could take this open source tool that the university is building, put an AI agent in front of it, let it rip, right? Let's go. Yeah. Yeah. So, so that was, so BTQ, which is a Canadian based post quantum encryption and security platform, raise 106.1 million post IPO equity, the reason they're not in the index is a way under a billion dollars or like 400 million or something like that valuation. And they, they came out in a weird way. They didn't do an official IPO launch. They went into the Canadian market and then got listed on the NASDAQ. It was a really weird situation. But then sandbox a Q just got a post quantum cryptography.
They raised a $500 million grant from the US Department of Commerce under the Chips and Science Act to support AI driven platform for discovering new semiconductor materials. So there's some stuff going on with the, with the federal government. Remember, sandbox a Q is a Google funded company. They don't even have, I don't even think they officially have a product yet. Okay. But then they get this $500 million grant from the US Department of Commerce, probably to build a product. On the way. Just saying. Just saying. There's a couple of other interesting ones here in these raises. Ninja one 400 million in the secondary market, like trying to stay afloat. So where does Ninja one go? Do you, I'm curious Jason, do you even see Ninja one around? I don't. Yeah. I don't think I've seen them anywhere. No. Yeah. Interesting.
Sayara on the data side, data security posture management raises 300 million. So there's still some good raises out there, right? You're still seeing money flow in, which is good, right? And you're seeing a lot of AI funding startup stuff in here. You know, Grace one, Alcatraz AI, like there's a whole bunch of, you know, AI strikers in here. So there's still funding coming in. But what I found really interesting was the number of acquisitions this last quarter is like three times the number of funding rounds. This is that consolidation point. It is, right? So it's really interesting. And everybody's buying at different levels, right? So Akamai, layer X. Remember, they just raised a bunch of money, right? So now they spent 205 million of that buying layer X security. Yeah. Yeah. So here we go. This is where that money goes. Yeah.
So there's a bunch. So I got a couple of highlight of here. There's some really interesting stuff. So Drago's acquires a phosphorus security, then they get acquired. Well, they get part ownership from Accenture. Okay. All that. And Accenture also acquired Run Zero. So they don't tell you how much went to Run Zero and how much went to Drago's. But I believe the combined investment was like $4.2 billion. Okay. So I'm pretty sure Drago's got a big chunk of that. Is part of that buy out, right? Because think about it. Drago's had raised over 400 million. Right. So let's just say it's a forexer. That's 1.71.8 billion right there in a $4.2 billion deal. Right. I don't think Run Zero was that high. They had only raised 20 million before. That's
HD Moores company that was Run Zero. So I do think a lot of the 4.2 billion that Accenture paid went into Drago's. Yeah. And then a portion of that went into Run Zero to pull that in. But it was an interesting acquisition and a set of pieces that kind of fit together. And I think we're going to see a little more of this. And you see it in certain cases where we have kind of these service companies or these managed security companies starting to buy technology because they have to figure out how to get more efficient and optimize for their service delivery. Well, at the end of the day, they need to be building a product that gives them monthly recurring revenue versus service revenue all the time. Right. I mean, yes, consulting is great. But you can't repeat that month over month. Right. There's going to be this ebb and flow if you're just a consulting firm. So they're building product at the end of the day. That's what they want to do. Right. And I mean, I look at I look at these acquisitions and my brain automatically goes to critical infrastructure. Think about what's happening in the critical infrastructure space. And what's about to happen in the critical infrastructure space? That's all operational technology.
IoT. I mean, how many attacks on water infrastructure have we seen? Hospitals that we've seen. And it's only going to get worse as these, you know, AI enabled threat actors start doing their thing. Yeah, I think it's a great move to get into the critical infrastructure space. But I mean, wow, what an app. So part of my opinion on that is yes, getting into the critical infrastructure space. But you know, this could be a whole whole episode. You know, AI is both the the attacker and can be the help, but not given the current resources that these companies have. Right. If you're if you're a wastewater management in, you know, East bomb pencil, Tucky, right? Yeah, if you're if you're handed an AI tool, you don't know what to do with it. They don't know what to do. And this to me is it needs to be a national initiative. I think we got to go back to like Estonia 2017 2018 and get our acts together as a country where we say, hey, let's offer up
some tax breaks to those labs that that, you know, do the training or maybe pay for kids to go to school right out of high school, learn this tech. And then they've got to pay back two years working in critical infrastructure. I think there's a level of innovation happening on the defensive side. There's a ton of innovation happening on the offensive side. Yeah, right. I think I said it on the last show. Yeah, offensive security historically was artisanal. Now it's industrial. Yeah, defense is still artisanal. It's not industrially yet. That's right. You need to put in the hard work to get industrial just like the offensive security folks are. We need that at the defensive side and we're not even close to there. No, no, I know. And I wonder if it's because it's easier to be on offense with some of these capabilities than it is on defense, right? Because now because now you have to understand what's coming. You have to understand the attack. You have to rationalize it. And this has been a problem, I think for a long time and I say it over and over and over again. It's a context problem, right? On defense, we need to understand all the context.
On offense, you don't necessarily need to. Yeah, right. Offensive sexy and in Pittsburgh, we've known for a long time that defense is how you win championships. And then we lost our way for a while and now we need to get back to it. Oh, that was great. There were a couple other quick things on the private side. So Snickglays off 90 employees. No surprise. I know they've been struggling. I think they have to reinvent themselves post frontier models. Like it's just it was I think super disruptive to them. And we had one death Salem cyber submitted paperwork to officially shut down operations. It is the first agentic AI sock to go under to die to die. It won't be the last, by the way, I'm just going to tell you that now. There's way to many agentic AI sock companies out there. This to me is just the tip of the iceberg, which is interesting because X of four seems to be really leaning in. They raised money and they're definitely
leaning into that space. So I don't know if it's going to be a matter of like a couple of winners as we all consolidate or how that's going to work. No, I tend to agree with you, Summer, right? You have to have a proven track record. You can't just come out and say I'm agentic AI sock and all the sudden people are going to start buying you, right? And if you can't show traction in revenue and in a path forward, you're not going to get the next round. And then you're going to go under or somebody's going to pick you up for pennies on the dollar because you have some interesting IP. But yeah, I think there will be some big winners in the space, but there's way too many of them and they all can't be winners. If you know what I mean, first funeral. Yes, it won't be the last first funeral on the agentic AI sock. We should have an LLM right the obituary. I am. Yeah, I'm going to, you know, I'm going to chat GPT or Claude right after. Yes, exactly.
Oh, thank you both for joining me today. Thank you everyone for watching and listening. We'll see you next week on Business Security Weekly. Thank you for watching. If you enjoyed this content and would like to find more, see what the rest of the Security Weekly Network has to offer. Visit securityweekly.com, forward slash, subscribe to find all of our shows and the latest episodes. Hope to see you on a future episode.
More episodes
More from Security Weekly Podcast Network (Audio)
9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - S...
Security Weekly Podcast Network (Audio)
It's More Secure When It's Disabled - PSW #943
Security Weekly Podcast Network (Audio)
Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Le...
Security Weekly Podcast Network (Audio)
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 -...
Security Weekly Podcast Network (Audio)