Validated Containment Architectures are here. →Explore

In the latest episode of “In Progress,” Aviatrix CEO Doug Merritt met with Eric McAlpine, Founder and CEO of Momentum Cyber, to talk about:  

  • Eric’s journey with Blackstone and the idea that led him to found Momentum Cyber 

  • The rise of AI security as a security class 

  • Recent trends in market deals and what they reflect about the accelerating rate of change in the industry 

  • The failure of detection alone and the real runtime control points of a network 

Momentum Cyber: Get Bigger and Go Faster

Doug and Eric discussed the roots of Momentum Cyber and how the firm came to sit at the center of one of the fastest-moving corners of tech. McAlpine left a senior post at Blackstone at age 39 and took a six-month sabbatical before he began building Momentum Cyber. He said the idea came together on a family trip to Costa Rica, where he started writing down thoughts about what a next-generation advisory firm would look like. 

"My engineering brain turned on," Eric said. "I wrote down the equation for momentum, mass times velocity. And it's a vector. Then I came to this theory: how could we help companies get bigger and go faster?" 

He picked cybersecurity because of how tangled the field had become. "If you really understand security, it's almost like a rainforest," he told Doug. "There's so much life in there, but man, can you die in a minute if you don't know what you're doing."  

They discussed how Eric's experience with M&A working on deals like the $2.1 billion RSA sale to EMC or Foundstone sale to McAffee gave him the foundation he needed to start Momentum Cyber. 

"Having a front row seat to [the Foundstone sale], really building the security practice at Citigroup over those six years, and then leaving in 2008 and then doing it again at Blackstone for another six years, really gave me the courage to go out and and plant a flag as the industry's first investment bank that was exclusively focused on this space," he said. "I knew there was a need. I just had to get to a point in my career where I felt like I was the one to go and do it. And that's why Momentum Cyber, and that's why we did it." 

The Era of the Mega Deal

Doug and Eric talked about the latest Momentum Cyber reports, including the latest Monthly Market Review, and Eric's insights into recent deals in the market. Eric and his team call the last three or four years "the era of the mega deal."  

"This is the first time that we've seen people step up to $10 billion plus deals very consistently," he said. "But there were only $8 billion+ deals all of last year, and only one in six deals have disclosed deal value." 

He explained how that uncertainty creates a certain "opaqueness in the market for the common observer." Despite that uncertainty, the pace of this year is rapid, with 218 deals in the first half of this year.  

"We're at a pace to exceed last year by another 10%," he said. "I wouldn't have predicted that."  

AI Security M&A Is Moving at Record Speed

Eric confirmed that rapid pace and backed it with deal data. Last year saw 10 AI security M&A deals; year to date in 2026, there have been 29. Extrapolated forward, he estimated 50 to 60 AI security M&A deals by year-end. Strategic acquirers like Akamai, CrowdStrike, and Palo Alto Networks are willing to spend hundreds of millions to fill their AI roadmap gaps because "the answer 'we're going to go and hire some engineers' is just not good enough and not fast enough for how fast this market is moving."

He called the velocity unprecedented: "We've had a category that didn't exist two years ago, was heavily financed last year, and moved into M&A motion this year. We've never seen that happen before in that fast."

Detection Alone Won't Close the Gap

Eric brought up detection. He acknowledged that the industry has been "exceptionally good at seeing these problems" for more than a decade, "but seeing a problem is not the same as stopping it." The most obvious AI use case in security is SOC automation, and he's lost count of the autonomous SOC startups. "That's just better detection, faster detection."

At the same time, he pointed to companies raising $150 to $180 million first rounds on prevention-oriented theses. He described a "flight to quality" in financing: overall deal volume is down, but dollars per deal are 10x what they were five or ten years ago. Investors are backing proven operators and giving them five times more capital than their last venture.

Doug shared that he hears at every conference and in every customer conversation, including the response to the recent breach disclosures, is the same refrain: detect faster, patch faster. He pushed back on that prescription. "I've been arguing for four months: that is not the recipe for success."

Eric noted that the adversary speed problem is real and not something to dismiss. "As long as the adversaries are going to use this technology, we must absolutely use this technology to defend ourselves," he said. But then he pointed to the infrastructure layer, referencing what he called an "architectural divide" the industry hasn't seen before. He said the average CISO doesn't yet have a full understanding of the problem at that scale. 

Architecture, Not Band-Aids

Doug argued the industry has been in "a loop of band-aids for a while" and has gotten away with it, but the current environment requires going back to first principles and thinking about security at the architectural level. He used the OpenAI/Hugging Face incident as a case study. An intelligent attacker broke out of a sandboxed environment, which is "a classic case for architecture." The sandbox had flaws, but the real question was how the attacker reached the production database and exfiltrated credentials so quickly without being stopped. "That's an architectural question," he said.

Eric agreed and raised the physical scale of the problem: the sprawl of data centers, the spend by the top 20 technology companies by market cap. "The architectural footprint is massive," he said.

Three Runtime Control Points 

Doug laid out his framework for the importance of network architecture. There are three foundational runtime control layers where you can actually stop an action in progress: the identity layer, the compute/endpoint layer, and the network layer. "Our whole tech world, whether it's OT or IT, is entities acting on compute, talking to entities acting on compute," he said.

Eric explained that he now thinks in terms of strategic control points rather than the old best-of-breed versus best-of-suite framework. Identity is the hot control point today, and he pointed to Palo Alto Networks making a billion-dollar-plus acquisition in identity after years of saying they weren't interested. He also flagged non-human identity, OT/IT convergence, and data as control points where platform companies are spending to maintain dominance.

Prediction: Follow the People and Follow the Money

Eric closed with one data point and one prediction. The data point: 86% of M&A volume this year has been driven by strategics, not private equity. Companies like ServiceNow, Accenture, and industrial firms are making large moves into cybersecurity, backed by the largest market caps the sector has ever seen.

His prediction: "Follow the people and follow the money." He pointed to Thomas Kurian leaving his post to join Google Cloud. Google was "considered a joke in security" before Kurian arrived. After he joined, Google acquired Mandiant and Wiz, and is now considered the secure cloud and the fastest-growing cloud company. Eric noted that some frontier AI lab companies have recently hired away talent from hyperscalers like Google and Oracle.  

His advice: track where those people go, and where the capital follows.

Listen to the full episode. 

Share This Article
Connect With Us

Ready to see Aviatrix in action?

Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.

Gartner Report

Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report

Download and gain actionable insights to advance your cloud security strategy.

Download Now!
Recent Articles
Cloud Security Network Architecture What It Is and Why the Perimeter Model Fails

Cloud Network Security Guide: What It Is, Why the Perimeter Failed, and What Comes Next

Aug 18, 202620 min read
451 Research Report: Aviatrix extends cloud security fabric to AI agents with containment platform launch

451 Research Report Profiles Aviatrix Containment Platform

Aug 13, 20264 min read
CrowdStrike's Layer 1 Is the Network: East West Traffic Security for AI Workloads Across Clouds

CrowdStrike's Layer 1 Is the Network: East-West AI Security

Aug 11, 202610 min read
Black Hat 2026: The Center of Gravity Moved

The Center of Gravity Moved: Black Hat 2026

Aug 07, 20264 min read

Keep Reading

Related Articles

Featured Categories

95a2292256ee0f5750aa745fc7d21d39c8ae2870

ACE Program

Explore Category
Rectangle 3966

Customers

Explore Category
5a9318112c7cc265fab072924a2acaa2122a1c9f

Cloud Network Security

Explore Category
Aws-card

AWS

Explore Category
partner_card

Partners

Explore Category
cloud networking heroes

Cloud Networking Heroes

Explore Category
azure_card

Azure

Explore Category
events_card

Events

Explore Category

Secure The Connections Between Your Clouds and Cloud Workloads

Leverage a security fabric to meet compliance and reduce cost, risk, and complexity.

Cta pattren Image