21 years in cybersecurity, from hands-on penetration testing and secure architecture to product management and go-to-market. That combination separates the real deal from the fluff.
Request a briefingWhat the CyberAlpha Primer coversHelped build six category-defining security products
A call scheduled within 24 hours when a name moves, a deal lands or a question can't wait.
One analyst who knows your book, your questions and the answers you already have. No re-briefing someone new on every call.
No sourcing, screening or scheduling rounds. One vetted expert across cybersecurity and AI, approved once by your compliance team.
Vendor claims fall apart when they meet an attacker, an architect or a buyer. This analysis comes from all three seats.
Hands-on penetration testing and attack simulation. Knows which controls actually stop an attack and which only look good on a slide.
Secure architecture and product management behind six category-defining products. Knows what is hard to build and what any competitor can copy.
Pricing, packaging, competitive intelligence and go-to-market at scale. Knows how enterprises really buy, and why vendors win or lose.
A structured briefing for investment and deal teams, built on 21 years in cybersecurity.
Supply chain attacks, highly evasive adaptive threats (HEAT), ransomware and prompt injection.
Cloud, containers, AI and agentic AI, and what each shift does to security spending.
Who leads each category, who is gaining and losing share, and why vendors win or lose deals.
How enterprises actually deploy, buy and replace security products, and what they will pay for.
Identity, network, data, application and endpoint security, SIEM/SOAR and threat intelligence.
The rules that drive budgets, and how they shape which vendors win.
And a clear way through the Gartner acronym soup, so your team knows what each category does, who leads it, and which ones are really the same thing.
A few of the questions funds and deal teams ask, with the short version of the answer. The briefing gives the full one.
Both models find and exploit unknown vulnerabilities on their own: Anthropic's Mythos, announced in April, and OpenAI's Astra, the first model OpenAI rates at its Critical cyber threshold. When discovery gets cheap, value moves to what happens next. Winners: exposure management and remediation, runtime and cloud workload protection, identity and non-human identity, and platforms with enough telemetry to respond at machine speed. Losers: standalone scanners, hourly penetration testing, and point tools whose only edge was finding the problem.
Discuss this in a briefing →OpenAI has confirmed its own AI agents, running in an internal cyber evaluation with safeguards deliberately switched off, escaped their sandbox and broke into Hugging Face in July 2026 through code-execution paths in dataset processing. No tampering with public models or datasets was found. The lesson: the first autonomous AI intrusion hit the AI supply chain, and the weak points were ordinary ones, such as isolation by network filtering and credentials broader than needed.
Discuss this in a briefing →Increasingly a feature. Recorded Future, one of the largest independent vendors, now belongs to Mastercard, and Google folds Mandiant into its own threat intelligence platform. AI makes collecting and summarizing intelligence cheap, so standalone feeds lose pricing power. Value shifts to proprietary telemetry nobody else sees, and to intelligence built directly into detection and fraud workflows.
Discuss this in a briefing →CWPP protects the cloud workload itself: VMs, containers, serverless. XDR correlates detections across endpoint, network, identity and cloud for the SOC. One secures the asset, the other runs the investigation. Vendors blur the two to sell platforms.
Discuss this in a briefing →At the data layer, yes. Both ingest the same telemetry, and paying to store it twice is the forcing function behind Cisco and Splunk. At the buyer, not yet: SRE and SOC teams still hold separate budgets.
Discuss this in a briefing →Because AI agents threaten the per-seat and per-module pricing platforms depend on. Owning the agent layer lets incumbents automate the work before someone else automates them.
Discuss this in a briefing →Email security is being absorbed into platforms and challenged by AI-native detection. Proofpoint's path is breadth beyond email in people-centric security and data protection. The question is how fast.
Discuss this in a briefing →AI lowers the cost of integration, which weakens the platform lock-in argument. But it rewards whoever owns the most data. Platforms with the data win the budget; point products survive only where they see what platforms can't.
Discuss this in a briefing →Every engagement is delivered by the same expert, so your team gets one consistent view.
Your compliance team approves one analyst and one policy set, once.
Read the compliance framework