The breach isn’t the problem. The spread is. →Free Assessment

Podcast
Episode |04
48:27Min

The New Physics of Cyber

In this episode of In Progress, CEO Doug Merritt sits down with Eric McAlpine, Founder and CEO of Momentum Cyber, the cybersecurity industry's first dedicated investment bank. Eric shares how he built Momentum after stints at Citigroup and Blackstone, and what the firm's deal data reveals about a market moving faster than anyone predicted — from billion-dollar mega deals becoming routine to an AI security M&A category that went from nonexistent to white-hot in under two years. With 218 deals in the first half of this year and strategic acquirers racing to buy what they can't build fast enough, Eric maps the forces reshaping the landscape. The conversation turns to a fundamental problem: detection alone isn't closing the gap. Doug and Eric argue that the industry's default playbook — detect faster, patch faster — misses the point, and that security needs an architectural reset. They lay out three runtime control points where threats can actually be stopped in progress: identity, compute, and network. Eric closes with a prediction: follow the talent moving between hyperscalers and AI labs, and follow the capital behind them.

Stay in the Loop

Get exclusive access to the latest conversations with cloud leaders, industry pioneers, and technology changemakers.

Subscribe and stay ahead of what's next.

Zero spam. Unsubscribe at any time.

In Progress Podcast

The New Physics of Cyber

Aug 18, 202648:27 minYouTubeSpotifyApple

Key Summary

  • AI security M&A is moving at unprecedented speed. A category that didn't exist two years ago jumped from 10 deals last year to a projected 50–60 by year-end, as companies like CrowdStrike, Palo Alto Networks, and Akamai spend hundreds of millions to fill AI roadmap gaps.
  • The mega deal era is accelerating. Cybersecurity M&A is on pace to exceed last year by 10%, yet most deal values remain undisclosed, making the market harder to read than it appears.
  • Detection without prevention is a dead end. The industry excels at seeing threats but struggles to stop them. Investors are responding, backing prevention-oriented companies with outsized funding rounds.
  • Security needs to go back to first principles. Three runtime control points — identity, compute/endpoint, and network — are the foundational layers where organizations can stop attacks in progress.

The Speaker

Doug Merritt spent seven years leading Splunk, the company that defined the detection era of cybersecurity, growing annual recurring revenue from $220 million to $3.12 billion. As Chairman, President, and CEO of Aviatrix, he now makes the case that detection is no longer enough. He has expanded the multicloud networking leader into Zero Trust protection for cloud networks and workloads, and in 2026 declared the arrival of the Containment Era, built on a simple thesis. Trust will be violated. The only question is whether your architecture bounds the blast radius when it is. Earlier, he held senior leadership roles at Cisco, SAP, and PeopleSoft.

Doug Merritt

Doug Merritt

LinkedIn Profile

The Guest

Eric is the Founder, CEO, and Managing Partner of Momentum Cyber, and a seasoned M&A and strategic advisor with nearly three decades of experience counseling boards and CEOs. Before launching Momentum, he led the Security and Internet banking teams at Blackstone and Citi, where he closed transactions with some of the biggest names in tech — including HP, IBM, Google, Oracle, Amazon, Dell, and many others. He's also a two-time founder and a decorated military engineer.

Eric McAlpine

Eric McAlpine

LinkedIn Profile
In Progress Podcast

Never Miss an Episode

Join thousands of cloud professionals following the stories, strategies, and hard-earned lessons from the architects driving enterprise transformation. Be the first to know when new episodes go live.

New Biweekly Episodes

Zero spam. Unsubscribe at any time.

Join cloud engineers and modern architects already tuned in.

Keep exploring

Related Episodes

Security for AI, Not AI for Security 
EP7 Title Card
07
YouTube
Security for AI, Not AI for Security 

Doug Merritt · Chief Executive Officer

- With every employee running ten or more AI agents, organizations now face thousands of credentialed non-human identities, and least privilege is harder to enforce than ever. - AI-enhanced security tools will be absorbed into everyday workflows, but securing AI systems themselves will remain a distinct and growing challenge. - Identity, network, and traditional security controls still apply to AI, but natural-language communication between agents creates blind spots legacy detection can't address. - When an agent goes rogue, you need the ability to revoke its identity, quarantine its compute, and cut its network access. When Hugging Face needed to stop a sandbox breakout, they reached for the network layer.

Listen Now
Building Security Programs Under Fire 
EP6 Title Card
06
YouTube
Building Security Programs Under Fire 

Doug Merritt · Chief Executive Officer

- Security expertise doesn't come from building security products. John's career pivot began when customers started finding vulnerabilities in Cisco's own tools — and his team couldn't explain how the attacks worked. - Building security at hypergrowth means flying while you build. John grew Zoom's security team from 10 to 300 during COVID, pausing all development to fix security bugs while fending off nation-state attackers. - Shift-left only works if you show up prepared. Run risk assessments early, join design meetings for high-risk features, and tune CI/CD tooling carefully — false positives destroy credibility with developers. - AI makes design reviews more comprehensive than any human. It can also generate proof-of-concept exploits in minutes instead of days, which means attackers have that same advantage. - Think containment by default, not just patch and pray. With AI accelerating vulnerability discovery and supply chain attacks putting compromised workloads directly into your environment, the vulnerability deficit means patching alone will never be enough.

Listen Now
How Zero Trust Was Born
EP5 V3 TITLECARD
05
YouTube
How Zero Trust Was Born

Doug Merritt · Chief Executive Officer

- Trust is a human emotion, not a network concept — and treating it as one creates the vulnerabilities attackers exploit. - Focus on "protect surfaces," not everything at once. Defend your most critical assets individually, and Zero Trust becomes incremental and non-disruptive. - All bad things happen inside of an allow rule. If something bad happened, a policy somewhere permitted it. - Stop buying products and start building policy. One consistent policy construct — who, what, when, where, why, and how — can apply across your entire environment. - Security won't improve until CEOs change how cybersecurity is incentivized. CISOs need real authority, not just accountability when things go wrong.

Listen Now
Cybercrime Runs Like a Fortune 500 Company
Cybercrime Runs Like a Fortune 500 Company
03
YouTube
Cybercrime Runs Like a Fortune 500 Company

Doug Merritt · Chief Executive Officer

- Cybercrime is organized like a business. Roles are specialized and clearly compensated, from malware developers to money launderers, making these networks resilient and hard for law enforcement to dismantle. - Ransomware economics are shifting. The cost of storing and servicing stolen data has led many groups to abandon encryption entirely in favor of extortion alone. - Lateral movement, not initial access, is the real threat. Incidents like Colonial Pipeline and Stryker show that how fast attackers spread internally matters more than how they got in. - Preparation is non-negotiable. Boards should know who's responsible for which decisions in the first 24 hours of an attack, well before one happens.

Listen Now
Assume Containment, Not Breach
Nick Reva
02
YouTube
Assume Containment, Not Breach

Doug Merritt · Chief Executive Officer

- Why Nick argues the industry should shift from "assume breach" to "assume containment" — and what that changes about incident response - The guardrails-not-gates philosophy that lets developers move fast without becoming security experts - How Nick's team found a workable path through an "impossible" secure-SDLC mandate on SpaceX's Falcon codebase - Applying Elon Musk's first-principles reasoning to break security problems down to their core "whys" - Why Nick sees cloud security footholds as a societal and economic risk, not just a technical one

Listen Now
Chris Hughes: Not Prevention, But Resiliency
EP01
01
YouTube
Chris Hughes: Not Prevention, But Resiliency

Doug Merritt · Chief Executive Officer

- CVEs are exploding — over 40,000 in 2025, with 2026 projections near 60,000 (some estimates up to 100,000) — while AI makes vulnerabilities easier to find and exploit. - Patching capacity has long lagged below 10% of the backlog; broken production risk and competing business priorities keep it there. - Security should shift from trying to prevent every incident to containing and recovering from the ones that happen. - "Human in the loop" doesn't scale against AI-driven attack volume — defenders need to fight AI with AI. - Security teams that act as collaborators, not blockers, avoid the shadow-IT workarounds that punitive policies create.

Listen Now