When code becomes something anyone can generate, attackers get the upgrade first. Global cybersecurity spending is now well into the hundreds of billions a year, yet ransomware, nation state attacks, and AI-generated deepfakes keep getting worse. So is all that money actually buying safety, or is the industry performing what one veteran founder calls the theater of cyber?

In this episode of Inside the Silicon Mind, we sit down with Evan Powell, founder and CEO of DeepTempo, to dismantle the assumption that AI is making defenders faster. Evan is a serial deep tech entrepreneur with more than twenty years of building companies, including StackStorm, the event-driven automation platform that lives on as a Linux Foundation project, and he has since launched the open source AI SOC Vigil and the SOCBench benchmark. DeepTempo builds LogLM, a foundation model pre-trained purely on logs (it never read Shakespeare, only logs) to identify attacker behavior with low false positives, and its reference partners span banking, telco, and national government.

You’ll hear why Evan believes defenders now operate on what he calls negative time, as attackers armed with distilled models hunt for novel vulnerabilities before a signature-based detection even exists. He explains why bolting a reasoning model onto detection produces poor accuracy and enormous cost at real-world volume, potentially more than a billion dollars a day at big telco scale, and why the NSA, Five Eyes agencies, and NIST are now all pointing toward anomaly detection instead. The conversation also covers the deepfake that slipped into Firas’s own inbound before compliance caught it, the incentive structures behind steak dinners and F1 sponsorships at RSA, and the risk every founder faces when the LLM their product depends on gets switched off.

Who this episode is for:

  • CISOs and security leaders questioning whether their spending is buying protection or box-checking
  • Founders building on top of LLMs who need to understand model dependency risk
  • Engineers and SOC practitioners dealing with signature-based tools that can’t see novel attacks
  • Investors evaluating AI security companies and separating system-level thinking from marketing noise
  • Executives at banks, telcos, and critical infrastructure providers facing AI-accelerated threats

What you’ll learn:

  • Why Evan argues AI is currently handing the advantage to attackers, not defenders
  • How signature-based defense went from weeks of lead time to what he calls negative time
  • Why general-purpose reasoning models may be the wrong tool for threat detection at scale
  • How purpose-trained models like LogLM approach detection through behavior rather than signatures
  • Why the cybersecurity industry’s incentive structure could be its biggest vulnerability, not its technology

Stay Tuned For Our Latest Episodes

Subscribe now and never miss an episode of Inside the Silicon Mind.

Start Listening Today!

Dive into game-changing conversations with the brightest minds in tech and business. Explore all episodes and start unlocking the secrets to success today.