<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[In Progress By Aviatrix]]></title><description><![CDATA[<p><b>In Progress By Aviatrix</b> features candid, unscripted conversations between Doug Merritt and provocative guests from business, government, and security. No scripts. No product pitches. Just frank and open dialogue about leadership, decision-making, and the realities of building organizations--naturally with some insights about the state of cybersecurity today. Designed to give you inspiration for your own career, role, and leadership execution.</p><p></p><p>In Progress: because nothing worth building is ever finished. And that's not a flaw. That's the point.</p><p></p><p>New episodes biweekly on LinkedIn, YouTube, Spotify, and Apple Podcasts.</p>]]></description><link>https://aviatrix.ai/in-progress/</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Mon, 07 Sep 2026 17:41:27 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/NrUOf2YM.rss" rel="self" type="application/rss+xml"/><author><![CDATA[Aviatrix]]></author><pubDate>Wed, 01 Jul 2026 15:19:16 GMT</pubDate><copyright><![CDATA[2026 Aviatrix]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Business]]></category><category><![CDATA[Technology]]></category><itunes:author>Aviatrix</itunes:author><itunes:summary>&lt;p&gt;&lt;b&gt;In Progress By Aviatrix&lt;/b&gt; features candid, unscripted conversations between Doug Merritt and provocative guests from business, government, and security. No scripts. No product pitches. Just frank and open dialogue about leadership, decision-making, and the realities of building organizations--naturally with some insights about the state of cybersecurity today. Designed to give you inspiration for your own career, role, and leadership execution.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In Progress: because nothing worth building is ever finished. And that&apos;s not a flaw. That&apos;s the point.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;New episodes biweekly on LinkedIn, YouTube, Spotify, and Apple Podcasts.&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>Aviatrix</itunes:name><itunes:email>yuval.reiss+435423@riverside.fm</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Business"/><itunes:category text="Technology"/><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/logos/60c8439f-220c-445d-9ffa-bf47f35ed5a0.jpeg"/><item><title><![CDATA[John Kindervag: How Zero Trust Was Born]]></title><description><![CDATA[<p>John Kindervag, creator of the Zero Trust model, joins host Doug Merritt on In Progress to trace Zero Trust's origin story — from LAN parties and firewall configurations to federal security mandates. John explains how getting fired for adding outbound rules to firewalls eventually led him to develop the framework at Forrester Research. The two dig into why trust is a vulnerability, how to protect what matters most, and why better policy — not more products — is the real fix. </p><p></p><p><b>Key Takeaways:</b> </p><ul><li>Trust is a human emotion, not a network concept — and treating it as one creates the vulnerabilities attackers exploit. </li></ul><ul><li>Focus on "protect surfaces," not everything at once. Defend your most critical assets individually, and Zero Trust becomes incremental and non-disruptive.</li></ul><ul><li>All bad things happen inside of an allow rule. If something bad happened, a policy somewhere permitted it. </li></ul><ul><li>Stop buying products and start building policy. One consistent policy construct — who, what, when, where, why, and how — can apply across your entire environment. </li></ul><ul><li>Security won't improve until CEOs change how cybersecurity is incentivized. CISOs need real authority, not just accountability when things go wrong. </li></ul>]]></description><guid isPermaLink="false">06324d96-b096-46b9-a947-ffc93fd7487c</guid><dc:creator><![CDATA[Aviatrix]]></dc:creator><pubDate>Wed, 02 Sep 2026 15:20:33 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/2b1aa6c3cadadf0fd8c6b6b69308511793fbdd9acc0f36dbb27d13ea58d5a543/eyJlcGlzb2RlSWQiOiIwNjMyNGQ5Ni1iMDk2LTQ2YjktYTk0Ny1mZmM5M2ZkNzQ4N2MiLCJwb2RjYXN0SWQiOiJmNzZlNDJmMy0xYTBhLTRiMDAtOWJiYi1hNWU3Yjk2NzIzNDgiLCJhY2NvdW50SWQiOiI2YTBkZjBhMzNiZTM0Y2NhYmJmYzU4ZjciLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE5ODNlYzI4M2RjNjRkODI5NTQ0YzI3L3l1dmFsLXRlc3RzLXN0dWRpby1DNUhrSC1jb21wb3Nlci0yMDI2LTktMl9fMTctMjAtMzMubXAzIn0=.mp3" length="95529735" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/episodes/06324d96-b096-46b9-a947-ffc93fd7487c/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;John Kindervag, creator of the Zero Trust model, joins host Doug Merritt on In Progress to trace Zero Trust&apos;s origin story — from LAN parties and firewall configurations to federal security mandates. John explains how getting fired for adding outbound rules to firewalls eventually led him to develop the framework at Forrester Research. The two dig into why trust is a vulnerability, how to protect what matters most, and why better policy — not more products — is the real fix. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Takeaways:&lt;/b&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Trust is a human emotion, not a network concept — and treating it as one creates the vulnerabilities attackers exploit. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Focus on &quot;protect surfaces,&quot; not everything at once. Defend your most critical assets individually, and Zero Trust becomes incremental and non-disruptive.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;All bad things happen inside of an allow rule. If something bad happened, a policy somewhere permitted it. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Stop buying products and start building policy. One consistent policy construct — who, what, when, where, why, and how — can apply across your entire environment. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Security won&apos;t improve until CEOs change how cybersecurity is incentivized. CISOs need real authority, not just accountability when things go wrong. &lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:49:45</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/logos/60c8439f-220c-445d-9ffa-bf47f35ed5a0.jpeg"/><itunes:episode>5</itunes:episode><itunes:title>John Kindervag: How Zero Trust Was Born</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Eric McAlpine: The New Physics of Cyber]]></title><description><![CDATA[<p>In this episode of In Progress, CEO Doug Merritt sits down with Eric McAlpine, Founder and CEO of Momentum Cyber, the cybersecurity industry's first dedicated investment bank. Eric shares how he built Momentum after stints at Citigroup and Blackstone, and what the firm's deal data reveals about a market moving faster than anyone predicted — from billion-dollar mega deals becoming routine to an AI security M&amp;A category that went from nonexistent to white-hot in under two years. With 218 deals in the first half of this year and strategic acquirers racing to buy what they can't build fast enough, Eric maps the forces reshaping the landscape.</p><p></p><p>The conversation turns to a fundamental problem: detection alone isn't closing the gap. Doug and Eric argue that the industry's default playbook — detect faster, patch faster — misses the point, and that security needs an architectural reset. They lay out three runtime control points where threats can actually be stopped in progress: identity, compute, and network. Eric closes with a prediction: follow the talent moving between hyperscalers and AI labs, and follow the capital behind them.</p><p></p><p><b>Key Takeaways</b></p><ul><li><b>AI security M&amp;A is moving at unprecedented speed.</b> A category that didn't exist two years ago jumped from 10 deals last year to a projected 50–60 by year-end, as companies like CrowdStrike, Palo Alto Networks, and Akamai spend hundreds of millions to fill AI roadmap gaps.</li><li><b>The mega deal era is accelerating.</b> Cybersecurity M&amp;A is on pace to exceed last year by 10%, yet most deal values remain undisclosed, making the market harder to read than it appears.</li><li><b>Detection without prevention is a dead end.</b> The industry excels at seeing threats but struggles to stop them. Investors are responding, backing prevention-oriented companies with outsized funding rounds.</li><li><b>Security needs to go back to first principles.</b> Three runtime control points — identity, compute/endpoint, and network — are the foundational layers where organizations can stop attacks in progress.</li></ul>]]></description><guid isPermaLink="false">4fbbdcaf-92c8-463b-907c-f6d0cdf626c8</guid><dc:creator><![CDATA[Aviatrix]]></dc:creator><pubDate>Wed, 19 Aug 2026 16:08:31 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/be684fa0f85c8f78f9a946142596820c82268fc3eb4b31784094429b6917f614/eyJlcGlzb2RlSWQiOiI0ZmJiZGNhZi05MmM4LTQ2M2ItOTA3Yy1mNmQwY2RmNjI2YzgiLCJwb2RjYXN0SWQiOiJmNzZlNDJmMy0xYTBhLTRiMDAtOWJiYi1hNWU3Yjk2NzIzNDgiLCJhY2NvdW50SWQiOiI2YTBkZjBhMzNiZTM0Y2NhYmJmYzU4ZjciLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE4NWQ1NzQ5NjRhOGNjYjU4OWRiMTQ3L3l1dmFsLXRlc3RzLXN0dWRpby1DNUhrSC1jb21wb3Nlci0yMDI2LTgtMTlfXzE4LTEwLTI4Lm1wMyJ9.mp3" length="93024487" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/episodes/4fbbdcaf-92c8-463b-907c-f6d0cdf626c8/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode of In Progress, CEO Doug Merritt sits down with Eric McAlpine, Founder and CEO of Momentum Cyber, the cybersecurity industry&apos;s first dedicated investment bank. Eric shares how he built Momentum after stints at Citigroup and Blackstone, and what the firm&apos;s deal data reveals about a market moving faster than anyone predicted — from billion-dollar mega deals becoming routine to an AI security M&amp;amp;A category that went from nonexistent to white-hot in under two years. With 218 deals in the first half of this year and strategic acquirers racing to buy what they can&apos;t build fast enough, Eric maps the forces reshaping the landscape.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The conversation turns to a fundamental problem: detection alone isn&apos;t closing the gap. Doug and Eric argue that the industry&apos;s default playbook — detect faster, patch faster — misses the point, and that security needs an architectural reset. They lay out three runtime control points where threats can actually be stopped in progress: identity, compute, and network. Eric closes with a prediction: follow the talent moving between hyperscalers and AI labs, and follow the capital behind them.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;AI security M&amp;amp;A is moving at unprecedented speed.&lt;/b&gt; A category that didn&apos;t exist two years ago jumped from 10 deals last year to a projected 50–60 by year-end, as companies like CrowdStrike, Palo Alto Networks, and Akamai spend hundreds of millions to fill AI roadmap gaps.&lt;/li&gt;&lt;li&gt;&lt;b&gt;The mega deal era is accelerating.&lt;/b&gt; Cybersecurity M&amp;amp;A is on pace to exceed last year by 10%, yet most deal values remain undisclosed, making the market harder to read than it appears.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Detection without prevention is a dead end.&lt;/b&gt; The industry excels at seeing threats but struggles to stop them. Investors are responding, backing prevention-oriented companies with outsized funding rounds.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Security needs to go back to first principles.&lt;/b&gt; Three runtime control points — identity, compute/endpoint, and network — are the foundational layers where organizations can stop attacks in progress.&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:48:27</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/logos/60c8439f-220c-445d-9ffa-bf47f35ed5a0.jpeg"/><itunes:episode>4</itunes:episode><itunes:title>Eric McAlpine: The New Physics of Cyber</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Keith Wojcieszek: Cybercrime Runs Like a Fortune 500 Company]]></title><description><![CDATA[<p>In this episode of In Progress, CEO Doug Merritt sits down with Keith Wojcieszek, former Chief of the Secret Service's Cyber Intelligence Section, to unpack what modern cybercrime actually looks like. Keith draws on his career-defining case against Roman Seleznev, once one of the world's most prolific credit card data traffickers, to show how cybercriminal operations now run like Fortune 500 companies or cartels, with developers, brokers, and money launderers each playing a defined, well-compensated role. He also traces how ransomware economics have shifted, why many groups have dropped encryption altogether in favor of simpler extortion, and how AI is making both attackers and defenders faster. </p><p></p><p>Doug and Keith also dig into what separates organizations that handle breaches well from those that don't: preparation. Drawing on incidents like the Colonial Pipeline shutdown and the Stryker attack, they argue the real vulnerability isn't how attackers get in, but how fast and far they can move once inside. It's a conversation about treating cybersecurity as a business risk rather than a purely technical one, and why boards need answers to hard questions before, not during, a crisis. </p><p></p><p><b>Key Takeaways</b> </p><ul><li>Cybercrime is organized like a business. Roles are specialized and clearly compensated, from malware developers to money launderers, making these networks resilient and hard for law enforcement to dismantle. </li></ul><ul><li>Ransomware economics are shifting. The cost of storing and servicing stolen data has led many groups to abandon encryption entirely in favor of extortion alone. </li></ul><ul><li>Lateral movement, not initial access, is the real threat. Incidents like Colonial Pipeline and Stryker show that how fast attackers spread internally matters more than how they got in. </li></ul><ul><li>Preparation is non-negotiable. Boards should know who's responsible for which decisions in the first 24 hours of an attack, well before one happens. </li></ul>]]></description><guid isPermaLink="false">9d61e077-38c3-40c9-8268-3afd353f66dd</guid><dc:creator><![CDATA[Aviatrix]]></dc:creator><pubDate>Wed, 05 Aug 2026 15:34:48 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f6bc85992a11f325ce1170a729163c4862a6139bf2867ad35303d0a45719609a/eyJlcGlzb2RlSWQiOiI5ZDYxZTA3Ny0zOGMzLTQwYzktODI2OC0zYWZkMzUzZjY2ZGQiLCJwb2RjYXN0SWQiOiJmNzZlNDJmMy0xYTBhLTRiMDAtOWJiYi1hNWU3Yjk2NzIzNDgiLCJhY2NvdW50SWQiOiI2YTBkZjBhMzNiZTM0Y2NhYmJmYzU4ZjciLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE3MzU4YWRiMDg5NGZjMmUwZWQxMDhhL3l1dmFsLXRlc3RzLXN0dWRpby1DNUhrSC1jb21wb3Nlci0yMDI2LTgtNV9fMTctMzctMTcubXAzIn0=.mp3" length="79735893" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/episodes/9d61e077-38c3-40c9-8268-3afd353f66dd/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode of In Progress, CEO Doug Merritt sits down with Keith Wojcieszek, former Chief of the Secret Service&apos;s Cyber Intelligence Section, to unpack what modern cybercrime actually looks like. Keith draws on his career-defining case against Roman Seleznev, once one of the world&apos;s most prolific credit card data traffickers, to show how cybercriminal operations now run like Fortune 500 companies or cartels, with developers, brokers, and money launderers each playing a defined, well-compensated role. He also traces how ransomware economics have shifted, why many groups have dropped encryption altogether in favor of simpler extortion, and how AI is making both attackers and defenders faster. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Doug and Keith also dig into what separates organizations that handle breaches well from those that don&apos;t: preparation. Drawing on incidents like the Colonial Pipeline shutdown and the Stryker attack, they argue the real vulnerability isn&apos;t how attackers get in, but how fast and far they can move once inside. It&apos;s a conversation about treating cybersecurity as a business risk rather than a purely technical one, and why boards need answers to hard questions before, not during, a crisis. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Takeaways&lt;/b&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cybercrime is organized like a business. Roles are specialized and clearly compensated, from malware developers to money launderers, making these networks resilient and hard for law enforcement to dismantle. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Ransomware economics are shifting. The cost of storing and servicing stolen data has led many groups to abandon encryption entirely in favor of extortion alone. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Lateral movement, not initial access, is the real threat. Incidents like Colonial Pipeline and Stryker show that how fast attackers spread internally matters more than how they got in. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Preparation is non-negotiable. Boards should know who&apos;s responsible for which decisions in the first 24 hours of an attack, well before one happens. &lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:41:32</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/logos/60c8439f-220c-445d-9ffa-bf47f35ed5a0.jpeg"/><itunes:episode>3</itunes:episode><itunes:title>Keith Wojcieszek: Cybercrime Runs Like a Fortune 500 Company</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Nick Reva: Assume Containment, Not Breach]]></title><description><![CDATA[<p>Nick Reva's path to becoming Global Director of Engineering Security at DoorDash started with a high schooler's curiosity about getting around network restrictions to reach Napster — a rabbit hole that turned into a career spanning Wrigley, PwC, SpaceX, and Snap, where he went from analyst to Snap's 32nd security hire and eventually turned what he learned into a Udacity course on cloud-native security and an upcoming book.<br /><br />In this episode of In Progress, Nick and Doug dig into why "assume breach" might be the wrong mindset for the cloud era, what it actually takes to build guardrails developers will use without a fight, and how Elon Musk's first-principles thinking reshaped the way Nick leads security teams — a conversation about engineering discipline, practical risk management, and why a cracked-open window in your cloud environment might matter more than the breach itself.<br /><br />Key takeaways:  </p><ul><li>Why Nick argues the industry should shift from "assume breach" to "assume containment" — and what that changes about incident response </li></ul><ul><li>The guardrails-not-gates philosophy that lets developers move fast without becoming security experts </li></ul><ul><li>How Nick's team found a workable path through an "impossible" secure-SDLC mandate on SpaceX's Falcon codebase </li></ul><ul><li>Applying Elon Musk's first-principles reasoning to break security problems down to their core "whys" </li></ul><ul><li>Why Nick sees cloud security footholds as a societal and economic risk, not just a technical one</li></ul>]]></description><guid isPermaLink="false">dd2962bc-d59b-49e9-a961-50396d48ae08</guid><dc:creator><![CDATA[Aviatrix]]></dc:creator><pubDate>Wed, 22 Jul 2026 17:01:23 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/5d42ff12ec3cfd2dc28f6994895e84d0e1960413c7826df73de7f9700635a678/eyJlcGlzb2RlSWQiOiJkZDI5NjJiYy1kNTliLTQ5ZTktYTk2MS01MDM5NmQ0OGFlMDgiLCJwb2RjYXN0SWQiOiJmNzZlNDJmMy0xYTBhLTRiMDAtOWJiYi1hNWU3Yjk2NzIzNDgiLCJhY2NvdW50SWQiOiI2YTBkZjBhMzNiZTM0Y2NhYmJmYzU4ZjciLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE2MGY3NjNiMTIzNDUwYTZiYTQzZTZmL3l1dmFsLXRlc3RzLXN0dWRpby1DNUhrSC1jb21wb3Nlci0yMDI2LTctMjJfXzE5LTEtMjMubXAzIn0=.mp3" length="88173653" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/episodes/dd2962bc-d59b-49e9-a961-50396d48ae08/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;Nick Reva&apos;s path to becoming Global Director of Engineering Security at DoorDash started with a high schooler&apos;s curiosity about getting around network restrictions to reach Napster — a rabbit hole that turned into a career spanning Wrigley, PwC, SpaceX, and Snap, where he went from analyst to Snap&apos;s 32nd security hire and eventually turned what he learned into a Udacity course on cloud-native security and an upcoming book.&lt;br /&gt;&lt;br /&gt;In this episode of In Progress, Nick and Doug dig into why &quot;assume breach&quot; might be the wrong mindset for the cloud era, what it actually takes to build guardrails developers will use without a fight, and how Elon Musk&apos;s first-principles thinking reshaped the way Nick leads security teams — a conversation about engineering discipline, practical risk management, and why a cracked-open window in your cloud environment might matter more than the breach itself.&lt;br /&gt;&lt;br /&gt;Key takeaways:  &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Why Nick argues the industry should shift from &quot;assume breach&quot; to &quot;assume containment&quot; — and what that changes about incident response &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;The guardrails-not-gates philosophy that lets developers move fast without becoming security experts &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;How Nick&apos;s team found a workable path through an &quot;impossible&quot; secure-SDLC mandate on SpaceX&apos;s Falcon codebase &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Applying Elon Musk&apos;s first-principles reasoning to break security problems down to their core &quot;whys&quot; &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Why Nick sees cloud security footholds as a societal and economic risk, not just a technical one&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:55</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/logos/60c8439f-220c-445d-9ffa-bf47f35ed5a0.jpeg"/><itunes:episode>2</itunes:episode><itunes:title>Nick Reva: Assume Containment, Not Breach</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Chris Hughes: Not Prevention, But Resiliency]]></title><description><![CDATA[<p>In the inaugural episode of In Progress, Aviatrix CEO Doug Merritt talks with Chris Hughes — CISA Cyber Innovation Fellow, author of <i>Software Transparency</i>, <i>Effective Vulnerability Management</i>, and <i>Securing AI Agents</i>, and founder of Resilient Cyber — about the forces reshaping security: exponential CVE growth, AI as both attacker and defender, the limits of "human in the loop," and why resilience now matters more than prevention.</p><p></p><p>Key Takeaways:</p><ul><li>CVEs are exploding — over 40,000 in 2025, with 2026 projections near 60,000 (some estimates up to 100,000) — while AI makes vulnerabilities easier to find and exploit.</li><li>Patching capacity has long lagged below 10% of the backlog; broken production risk and competing business priorities keep it there.</li><li>Security should shift from trying to prevent every incident to containing and recovering from the ones that happen.</li><li>"Human in the loop" doesn't scale against AI-driven attack volume — defenders need to fight AI with AI.</li><li>Security teams that act as collaborators, not blockers, avoid the shadow-IT workarounds that punitive policies create.</li></ul>]]></description><guid isPermaLink="false">5c1aeaef-c60d-44f3-b2df-e8fe18c08c40</guid><dc:creator><![CDATA[Aviatrix]]></dc:creator><pubDate>Wed, 08 Jul 2026 17:16:40 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/9e44f260b761fbac2c36df221090a675f1529ac3c0205cd3c70ad4ccb2df096d/eyJlcGlzb2RlSWQiOiI1YzFhZWFlZi1jNjBkLTQ0ZjMtYjJkZi1lOGZlMThjMDhjNDAiLCJwb2RjYXN0SWQiOiJmNzZlNDJmMy0xYTBhLTRiMDAtOWJiYi1hNWU3Yjk2NzIzNDgiLCJhY2NvdW50SWQiOiI2YTBkZjBhMzNiZTM0Y2NhYmJmYzU4ZjciLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0ZTg1Zjk5ZWNiNmNjN2I5NGE5NTUyL3l1dmFsLXRlc3RzLXN0dWRpby1DNUhrSC1jb21wb3Nlci0yMDI2LTctOF9fMTktMTYtNDEubXAzIn0=.mp3" length="84054247" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/episodes/5c1aeaef-c60d-44f3-b2df-e8fe18c08c40/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In the inaugural episode of In Progress, Aviatrix CEO Doug Merritt talks with Chris Hughes — CISA Cyber Innovation Fellow, author of &lt;i&gt;Software Transparency&lt;/i&gt;, &lt;i&gt;Effective Vulnerability Management&lt;/i&gt;, and &lt;i&gt;Securing AI Agents&lt;/i&gt;, and founder of Resilient Cyber — about the forces reshaping security: exponential CVE growth, AI as both attacker and defender, the limits of &quot;human in the loop,&quot; and why resilience now matters more than prevention.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Key Takeaways:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;CVEs are exploding — over 40,000 in 2025, with 2026 projections near 60,000 (some estimates up to 100,000) — while AI makes vulnerabilities easier to find and exploit.&lt;/li&gt;&lt;li&gt;Patching capacity has long lagged below 10% of the backlog; broken production risk and competing business priorities keep it there.&lt;/li&gt;&lt;li&gt;Security should shift from trying to prevent every incident to containing and recovering from the ones that happen.&lt;/li&gt;&lt;li&gt;&quot;Human in the loop&quot; doesn&apos;t scale against AI-driven attack volume — defenders need to fight AI with AI.&lt;/li&gt;&lt;li&gt;Security teams that act as collaborators, not blockers, avoid the shadow-IT workarounds that punitive policies create.&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:43:47</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f76e42f3-1a0a-4b00-9bbb-a5e7b9672348/logos/60c8439f-220c-445d-9ffa-bf47f35ed5a0.jpeg"/><itunes:episode>1</itunes:episode><itunes:title>Chris Hughes: Not Prevention, But Resiliency</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>