
Hosted by Paul Shomo
Interviews with founders, startup-advising CISOs, venture capitalists, and analysts discussing the issues of cybersecurity, new threats, and emerging technology.
17 episodes · publishes fortnightly · latest 2023-10-23 · ~25 min/episode
Rank
#427
Substance
77.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#427 of 6182
Substance
Top 7%
outscores 93% of the index
Genealogy of Cybersecurity - Startup Podcast ranks #427 on The B2B Podcast Index with a substance score of 77.0 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Yoni is a co-founder/CEO of Valence Security with prior experience building and exiting a cybersecurity startup (SCADA Fence) and military cyber roles, giving him legitimate practitioner credibility. However, he is primarily a vendor pitch guest rather than a battle-hardened operator reflecting on lessons learned at a major organization, and the conversation doesn't extract enough of his hard-won operational experience.
Averaged across 5 recently scored episodes, with cited evidence.
The episode covers several concrete technical concepts - shadow SaaS integrations, OAuth token theft via vendor compromise (Heroku/CircleCI), decentralized IT vs. centralized security, and the difference between posture management and integration-layer security. However, significant portions repeat the same shadow integration concept across multiple explanations, and the discussion lacks novel depth on remediation mechanics or financial impact metrics that would help operators prioritize risk.
“They breached organizations like Heroku and traverse the iron circle CI, which are very legitimate vendors that most organizations in the world would trust with access to their code repositories. They stole their OAuth tokens and API keys, and they leveraged them in order to gain unauthorized access to GitHub repositories”
“The difference between what we're doing and what the more password management solutions are doing is that we go beyond that. We look at third party integrations, OAuth connected applications, and third party apps managed identities”
The framing of lateral SaaS-to-SaaS integrations as a distinct security surface is relatively fresh and underexplored compared to traditional identity/access and posture management. However, the core insights (decentralized IT creates risk, vendors get breached, shadow tools proliferate) are known within security circles. The guest avoids strong contrarian positions and doesn't challenge conventional thinking in unexpected ways.
“In the modern decentralized IP model, where every business user is adopting and managing their best of breed SaaS, IT and security don't really have the full control and visibility into all the changes that are made within these applications”
“The vast majority of companies in the world never go and off board these unnecessary vendors”
Yoni is a co-founder/CEO of Valence Security with prior experience building and exiting a cybersecurity startup (SCADA Fence) and military cyber roles, giving him legitimate practitioner credibility. However, he is primarily a vendor pitch guest rather than a battle-hardened operator reflecting on lessons learned at a major organization, and the conversation doesn't extract enough of his hard-won operational experience.
“My name is yoni. I'm one of the cofounders and the CEO of valence”
“Before I started a company called the SCADA fence focused on industrial IoT cybersecurity. And beforehand, they served for several years in the morning intelligence forces in various cyber related positions during the military service”
The episode names specific real-world breach cases (Heroku/CircleCI OAuth token theft, LastPass, SolarWinds, GitHub) and real tools (Gong, Calendly, Office 365, Zapier, Microsoft Power Platform). However, there are no concrete metrics on breach frequency, financial impact, remediation timelines, or customer data (e.g., how many shadow integrations a typical Fortune 500 discovers, what % lead to breaches). The depth of case-study analysis is shallow.
“They breached organizations like Heroku and traverse the iron circle CI”
“Even GitHub reach directly LastPass was preached over the past couple of last year a few times”
The host (Paul Shomo) asks solid architectural questions - how Valence differs from posture management, what data flows laterally, why centralized security fails with decentralized IT - and attempts to clarify the mesh concept. However, the host rarely pushes back on claims, accepts vendor framing uncritically, and doesn't challenge the guest on remediation trade-offs, customer friction, or whether the decentralized security model he pitches is actually feasible at scale.
“Could you kind of describe what you're being calling the shadow SaaS assess integrations problem?”
“Are you more on the detection response site or are you more on the protection side?”
First period on the Index - history builds from here.
9 scored on substance · 17 tracked in total.
Ep 16. Varun Badhwar on Pioneering Security Posture Management, and the Story of RedLock
2023-10-23 · 28 min
Ep. 15 Founder Mike Fey on Incubating Startups, AI and the Future of Web Browsing
2023-10-10 · 24 min
Ep 14. Privacy is in the Code: Relyance AI's Solution for DevOps Data Flows
2023-09-25 · 29 min
Ep 13. Zama on the Holy Grail of AI Privacy, Fully Homomorphic Encryption
2023-09-12 · 29 min
Ep 11. Valence Security on SaaS-to-SaaS Mesh, Shadow Integrations and Generative AI
2023-08-08 · 24 min
Ep 10. Endor Labs on Code Vulnerabilities, Sketchy Open Source Developers, and Software Supply Chain
2023-07-24 · 27 min
Ep 9. Concentric AI on NLP, ChatGPT, and Data Security Posture Management
2023-07-11 · 22 min
Ep. 8 CISO Sebastian Goodwin on Advising DSPM and Automation Startups
2023-06-26 · 31 min
Ep 7. Security Practitioner Trends from 2,400 RSA Conference Submissions
2023-06-13 · 19 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/genealogy-of-cybersecurity-startup-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/genealogy-of-cybersecurity-startup-podcast/badge.svg" alt="Ranked #49 on The B2B Podcast Index" width="360" height="136" />
</a>Track Genealogy of Cybersecurity - Startup Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.