In the latest episode of “In Progress,” Aviatrix CEO Doug Merritt met with Eric McAlpine, Founder and CEO of Momentum Cyber, to talk about:
Eric’s journey with Blackstone and the idea that led him to found Momentum Cyber
The rise of AI security as a security class
Recent trends in market deals and what they reflect about the accelerating rate of change in the industry
The failure of detection alone and the real runtime control points of a network
Momentum Cyber: Get Bigger and Go Faster
Doug and Eric discussed the roots of Momentum Cyber and how the firm came to sit at the center of one of the fastest-moving corners of tech. McAlpine left a senior post at Blackstone at age 39 and took a six-month sabbatical before he began building Momentum Cyber. He said the idea came together on a family trip to Costa Rica, where he started writing down thoughts about what a next-generation advisory firm would look like.
"My engineering brain turned on," Eric said. "I wrote down the equation for momentum, mass times velocity. And it's a vector. Then I came to this theory: how could we help companies get bigger and go faster?"
He picked cybersecurity because of how tangled the field had become. "If you really understand security, it's almost like a rainforest," he told Doug. "There's so much life in there, but man, can you die in a minute if you don't know what you're doing."
They discussed how Eric's experience with M&A working on deals like the $2.1 billion RSA sale to EMC or Foundstone sale to McAffee gave him the foundation he needed to start Momentum Cyber.
"Having a front row seat to [the Foundstone sale], really building the security practice at Citigroup over those six years, and then leaving in 2008 and then doing it again at Blackstone for another six years, really gave me the courage to go out and and plant a flag as the industry's first investment bank that was exclusively focused on this space," he said. "I knew there was a need. I just had to get to a point in my career where I felt like I was the one to go and do it. And that's why Momentum Cyber, and that's why we did it."
The Era of the Mega Deal
Doug and Eric talked about the latest Momentum Cyber reports, including the latest Monthly Market Review, and Eric's insights into recent deals in the market. Eric and his team call the last three or four years "the era of the mega deal."
"This is the first time that we've seen people step up to $10 billion plus deals very consistently," he said. "But there were only $8 billion+ deals all of last year, and only one in six deals have disclosed deal value."
He explained how that uncertainty creates a certain "opaqueness in the market for the common observer." Despite that uncertainty, the pace of this year is rapid, with 218 deals in the first half of this year.
"We're at a pace to exceed last year by another 10%," he said. "I wouldn't have predicted that."
AI Security M&A Is Moving at Record Speed
Eric confirmed that rapid pace and backed it with deal data. Last year saw 10 AI security M&A deals; year to date in 2026, there have been 29. Extrapolated forward, he estimated 50 to 60 AI security M&A deals by year-end. Strategic acquirers like Akamai, CrowdStrike, and Palo Alto Networks are willing to spend hundreds of millions to fill their AI roadmap gaps because "the answer 'we're going to go and hire some engineers' is just not good enough and not fast enough for how fast this market is moving."
He called the velocity unprecedented: "We've had a category that didn't exist two years ago, was heavily financed last year, and moved into M&A motion this year. We've never seen that happen before in that fast."
Detection Alone Won't Close the Gap
Eric brought up detection. He acknowledged that the industry has been "exceptionally good at seeing these problems" for more than a decade, "but seeing a problem is not the same as stopping it." The most obvious AI use case in security is SOC automation, and he's lost count of the autonomous SOC startups. "That's just better detection, faster detection."
At the same time, he pointed to companies raising $150 to $180 million first rounds on prevention-oriented theses. He described a "flight to quality" in financing: overall deal volume is down, but dollars per deal are 10x what they were five or ten years ago. Investors are backing proven operators and giving them five times more capital than their last venture.
Doug shared that he hears at every conference and in every customer conversation, including the response to the recent breach disclosures, is the same refrain: detect faster, patch faster. He pushed back on that prescription. "I've been arguing for four months: that is not the recipe for success."
Eric noted that the adversary speed problem is real and not something to dismiss. "As long as the adversaries are going to use this technology, we must absolutely use this technology to defend ourselves," he said. But then he pointed to the infrastructure layer, referencing what he called an "architectural divide" the industry hasn't seen before. He said the average CISO doesn't yet have a full understanding of the problem at that scale.
Architecture, Not Band-Aids
Doug argued the industry has been in "a loop of band-aids for a while" and has gotten away with it, but the current environment requires going back to first principles and thinking about security at the architectural level. He used the OpenAI/Hugging Face incident as a case study. An intelligent attacker broke out of a sandboxed environment, which is "a classic case for architecture." The sandbox had flaws, but the real question was how the attacker reached the production database and exfiltrated credentials so quickly without being stopped. "That's an architectural question," he said.
Eric agreed and raised the physical scale of the problem: the sprawl of data centers, the spend by the top 20 technology companies by market cap. "The architectural footprint is massive," he said.
Three Runtime Control Points
Doug laid out his framework for the importance of network architecture. There are three foundational runtime control layers where you can actually stop an action in progress: the identity layer, the compute/endpoint layer, and the network layer. "Our whole tech world, whether it's OT or IT, is entities acting on compute, talking to entities acting on compute," he said.
Eric explained that he now thinks in terms of strategic control points rather than the old best-of-breed versus best-of-suite framework. Identity is the hot control point today, and he pointed to Palo Alto Networks making a billion-dollar-plus acquisition in identity after years of saying they weren't interested. He also flagged non-human identity, OT/IT convergence, and data as control points where platform companies are spending to maintain dominance.
Prediction: Follow the People and Follow the Money
Eric closed with one data point and one prediction. The data point: 86% of M&A volume this year has been driven by strategics, not private equity. Companies like ServiceNow, Accenture, and industrial firms are making large moves into cybersecurity, backed by the largest market caps the sector has ever seen.
His prediction: "Follow the people and follow the money." He pointed to Thomas Kurian leaving his post to join Google Cloud. Google was "considered a joke in security" before Kurian arrived. After he joined, Google acquired Mandiant and Wiz, and is now considered the secure cloud and the fastest-growing cloud company. Eric noted that some frontier AI lab companies have recently hired away talent from hyperscalers like Google and Oracle.
His advice: track where those people go, and where the capital follows.
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.
Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report
Download and gain actionable insights to advance your cloud security strategy.





















