← All transcripts
EP. 14

Inside the Verizon DBIR Report w/ Alex Pinto

August 11, 2026 · 56 min ·Alex Pinto
Watch episode on YouTube
~59 min read · 161 exchanges
Mehul 00:00.97

Alex Pinto it's so nice to have you on the Noist to Signal podcast. Welcome.

Alex Pinto 00:05.782

Yeah, no, it's great to be here. Thanks for having me.

Mehul 00:08.608

Alex, you are one of the key authors of the Verizon DBIR report. It's one of it is the gold standard report that everyone in the industry waits for every year. And you've been doing this for years. I'm curious, you know, how has this journey been? When did when did you get involved with the DBIR report project?

Alex Pinto 00:31.914

So I've I've been so the DBI has been around for nineteen years, right? I cannot claim to be have been there for the whole of it. I actually joined Verizon, I'm gonna say I think it was eight or nine years ago. I actually had a quote unquote traditional normal network security product startup that got acquired by Verizon. And that's kind of how I became a part of the company. And I ended up I mean I always admired the report.

Right. Of course everyone in the industry is aware of it. And I got a chance to get involved in it, you know, a couple of years in into my my you know, tenancy at Verizon. And you know, I just fell in love with it. I just just you know, get get the chance now to lead the team and and shape the direction of where where the research goes, the things we talk about. And so it's been it's been great, it's been amazing.

Mehul 01:01.048

Yeah, we

Mehul 01:25.976

Do you have a sense of what is the origin story of the D BI report when did when it got created in nineteen years ago? Like what was driving what is the driving force for for the report? Was it mostly a marketing campaign or was it something that Verizon was seeing that no one was talking about?

Alex Pinto 01:44.166

I think I think that's actually a good story. because the it's i mean it's a very common story when you think about it. This the initiative again was was led by like threat intelligence researchers inside of the Verizon cybersecurity practice, right? Ver Verizon business cybersecurity practice, right? It's been around since forever. And they really wanted to do it. They had so d the kind of the original authors they were led by a PhD at the group called Dr.

Dr. Peter Tippett. And there were two people working with them. main there were smart people, but mainly like Wade Baker and and David Highlander. And they really wanted to do this. They had the data because of like a past like instant response engagements that Verizon had had. So the first DBIR actually covers like two years of Verizon instant response data. And I can tell you, marketing fought tooth and nail for it not to get published.

They tried so hard. They were so scared. Because nobody had done anything like that before. You have to understand that. Right? It's gonna get us in trouble with the customers, right? And

Mehul 02:47.938

Yeah.

And it it is always easy to get perceived as a vendor report. this is Verizon talking its own shop, it is it's the it's

Alex Pinto 02:58.188

Info.

But to your point, right? Twenty years ago, there weren't that many of them. This was actually unique at the time. It wasn't the first one, there were kind of few, but it was like everybody hates vendors' reports today in general because there's like a thousand of them. Every single vendor has to have one. But back then it was really unique. It was really an innovative idea. And so the bottom line is the thing launched.

Mehul 03:07.042

Yeah. Yeah.

Alex Pinto 03:25.494

It was incredibly successful and that everybody was for it, has been for it all along, right? Marketing. Yes, of course, it was my idea. It was a great thing that we have done, accomplished here. But but long story short, I think it was really something that was needed at the time, something that really nobody had really tried to do. And again, even today, if you if you read it, of course you have to understand, this was almost 10 years ago. It's it holds up pretty well. it helps it helps our

Mehul 03:29.494

for

Alex Pinto 03:54.74

not helps that the kind of the problems are roughly the same still, even 20 years later. But it's cle I'm glad we got a chance to continue to evolve, right? The I think the real turning point for the report after the first couple of issues is that on the third issue, we actually started getting external data contributors, right? So the third year was the first year the the vra the the US Secret Service joined

And provided us anonymized instant data from what they were seeing, the investigations that they were doing, a lot of financial fraud stuff, which is still their bread and butter. And and that really opened the doors, right? Because everybody saw how interesting it was to have not only data from Verizon, but from everybody else. And it started building the trust that the community has in it, right? I'll tell you, right, when you open, you talk to someone and say, Hey, would you like to share data with me?

Mehul 04:39.416

Hmm.

Alex Pinto 04:50.232

Are you crazy? Why would I share data with you? Well, the Secret Service trust us. It usually diffuses most of the arguments that you get on the kind of on the fly. I mean, I wasn't there at the time. I wonder how interesting those conversations were, but they were incredibly successful at getting people on board and again growing the the kind of the the scope that the report is able to work.

Mehul 04:50.723

Never.

Mehul 05:13.27

Alex, the question I have for you is this, you know, you're right that it started with the Verizon data. you know, Secret Service came in, they gave gave you some data, then other vendors chimed in, the FBI probably came in, they gave them the data. And now that's as this has become like a massive undertaking, right? Again, if I if I just from somebody's from the outside looking in, you know, it seems like this Verizon D BR report is a massive undertaking. A lot of data gets processed, a lot of

vendor coordination has to happen. Hey, you guys, you have to send me the data by such and such date. And I have to have you have to process the data, you have to connect the dots between the data, between somebody else's data, and so on and so forth. So my question to you, how big is the team and like what is the composition of the team? It feels like, you know, at least when you look at the quality of the report, it looks like this is like a 50% team that is like dedicated to process the data, making sense of the data and going from there. So I'm curious like

No, what is how big is the team? What is the composition of the team? Is it mostly writers? Is it is it engineers? What say you?

Alex Pinto 06:13.912

So the core authoring team is four people, right? But they are these are four people that are dedicated on putting the report together every single year. We actually work all year round to be able to get this thing out of the door, you know, once a year. And and I mean of course there are literally hundreds of people inside Verizon that support the thing getting out, right? Between like

Mehul 06:40.034

Nust.

Alex Pinto 06:42.202

media outreach and kind of you know we don't do we definitely don't do the diagramming right we're not you're not layout folks there's there's a marketing agency that is hired to do all the the visual work and and the layout. We do we do we do the core team does generate the figures ourselves, right? The figures are we're very we try to be very precise, we're very statistically minded. We want to make sure the error rate they mean something.

So we do create all the figures ourselves and it just gets like into an SVG and then goes into Adobe or whatever the thing that they they create those things today, right? But it's mainly and they're we're all technical in the sense that we're all I mean I'd say p current slash previous. I mean I haven't done instant response in a in handful of years now, maybe more than 10 years, but we're all instant responders. We've all done the work, right?

And most of us, I'd say, you know, three fourths of the team actually actively develop, are actually engineers, we're developing the code that analyzes the data, we are, you know, developing the analysis, we are creating new views or new dashboards that we can work through with the data. And that's core, right? Because you know, writing is incredibly hard, but figuring out what to write is a little bit harder even, right?

Mehul 08:04.328

That that is the question I have. Like somebody has to own the narrative. Somebody has to write this story. Somebody has to like, you know, that you know, somebody has to look at the big picture and tell the narrative for this year. This is what we are seeing. So that is part of the four teams. And and is this team are these yeah, and this team is is this composed of like data scientists and engineers and writers and you know, kind of doing some of the work across the board.

Alex Pinto 08:19.64

Everybody does it, yeah.

Alex Pinto 08:32.598

Yeah, we w I mean we can't we cannot afford with with four put people, we cannot afford to have someone who doesn't do everything, if that makes sense. Right. and but it's it's it's great, right? And if we have evolved the way to be clear, we wouldn't be able to pull this off without like literal literal decades of experience and automation, right? I mean, I think the

Mehul 08:41.55

Thank you.

Alex Pinto 09:01.75

Again, the it's like I said, four people, right? The the youngest quote unquote has been has been with us for six years, right? That's how much you know accumulated experience and what we do. One of the team members is David Highlander, which I mentioned before. He has written every single one of them, right? He knows intimately, you know, you know, what's the kind of message that's gonna connect or not, right? He has long running relationships with a lot of our data contributors, right?

And this is key, right? A lot of the it's a very human endeavor, even though there's so much automation, right? people intrinsically so they trust the DBIR that the DBIR will be able to represent their data correctly, that we'll be able to represent the the and that's the important thing, right? yeah, we have to craft a narrative. The narrative has to be true. We have to represent the the the the truth of what's going on. And so we have to invite a lot of different perspectives.

Mehul 09:52.654

Yeah, yeah, yeah.

Alex Pinto 10:00.832

into what do you think, how does this going, you know, but we and I think one of the things that people respect a lot, and it's a really big focus of our of the the work that we do on the report, is kind of that that old joke like someone is telling you that it's raining, someone is telling you that's not raining. You know, my job is not to tell what they told me. My job is to stick my arm out of the window and tell you, it's actually raining or not. Right? So a lot of what we do is sticking the arm out, getting the data

And like, okay, we all have this conception that this is the good thing or this is the bad thing, this is what it it appla it how it plays out. There's a there's a joke. It's not a joke, right? It's it's it's a it's people bring it to up to me frequently, right? when I when I'm doing like a general presentation of the DBR, I'm like, you know, you know what your problem is? Your problem is not insider actors, your problem is external. So external based attacks has been number one.

Since the beginning of time, since the beginning of history, as far as the DBR is concerned, every single data point we have is like external attacks, like sixty, eighty percent, depending on the year. And so all the stories you have heard across your life around the insider threat is the most common, is the most it's not true. Right? And so but again, we're sticking our arm out, right? We're gathering data from again, almost now a hundred data contributors to be able to

to to make that statement and and and and and prove it, right?

Mehul 11:30.317

Alex, you talk about you talk about jokes and the thing that comes to mind is the DBIR has this joyful and fun vibe to it. And my question is, is that intentional?

Alex Pinto 11:42.32

100%. 100%. And it has one of the one thing we're and it's incredibly hard, I think, in cybersecurity has two problems, I think. One of first of all, it's it's very dense, right? It's it's you know, it can get you can get very much in the weeds very quickly, and it's also very bleak when you think about it, right? We're we're here.

you know, talking about all the bad stuff that happened throughout the year and and again trying to

Mehul 12:13.493

Yeah, we just had we just had the we just had the hugging face incident which is blowing up.

Alex Pinto 12:17.654

Yeah, and people are going insane at the hugging facing, right? I mean the don't don't don't sell your your stock. The world's not gonna fall apart. This is not the time to stock on ten goods yet, right? We're we're we're talking through it. It's it's gonna be fine.

Mehul 12:31.745

The the funny the funny comment that comes to mind is in the report it says, ransomware is still the yoga pants of cybersecurity. Ubiquitous, stubbornly popular and appearing in unexpected places near you. So I don't know who wrote it. I don't know who wrote it, but it is like it is super funny.

Alex Pinto 12:45.302

Yeah, I I

Alex Pinto 12:51.19

Yeah, I mean we I I'll I'll tell you, you know, as as a fact, everybody on the DBIR hates ransomware with a like red hot rage, right? And it's one of those things where, you hate it because it's a it's a bad thing, it's you know, hurting companies, it is you know, untold damages and concern. No, I hate because we we we wanna stop talking about it. It's so annoying.

It's o the only thing that happens, right? And you know, we wish I don't know. It's one of those things like the monkey pod thing, right? I wish ransomware wasn't a thing anymore, and then something ten times worse shows up, right? But but the humor is very much intentional. everybody writes the jokes, right? If you read the DBR long enough, you can tell, this is an Alex joke or this is a Dave joke, right? but we can

We even though we we kind of we we kinda all write at the same time as in it's breakout in session sections and you you can see a little bit of voice drift as who is writing the we all go into each other's sections and that jokes as well. because it's fun. It's it's it's great. And you you need to break you need to you break the flow. You need to make sure that people are engaged throughout as well. Yeah.

Mehul 14:06.933

Is the

Mehul 14:12.353

You have to make it funny. Yeah. Otherwise, you know, cybersecurity is dreadful and boring, you know you know, you have to make it funny. I'm curious, w what is the start date? Like how long before the official report goes out does the work start, or is it like an ongoing process? Or is there like a initial kick off? Is there like a kickoff date? Okay. For twenty thirty seven we start today.

Alex Pinto 14:27.378

It it's pretty much ongoing.

Alex Pinto 14:33.708

Yeah, it's it's kind of like I'll give you some like broad things. I mean we're we're discussing I mean, we start talking about the the the next one as soon as we release the the current one, pretty much. Because the pro the but I'll tell you why.

Mehul 14:45.311

It's like the it's like the it's like the presidential campaign. As soon as the campaign is done, you talk about who's gonna be the next president.

Alex Pinto 14:52.12

So y yes. But the the the thing for us is because at the end, at kind of the end of releasing the report, we're so you know laser focused on it that we kind of become blind to everything else that's going on. So right after we we release, it's more of a like what did we miss? Right? What were the things that people were talking about over the over the past like two or three months?

Mehul 15:04.365

Focus.

Alex Pinto 15:21.176

'Cause we weren't really paying attention. And and and so these are things we're gonna be talking about on the next one. So are we sure we know everything? We have the the right partners to talk about this. And so there's like a I'd say a three to four month period where we are like, okay, what's the you know, kinda what's the it's like e imagine you go to a I mean it's a very idealized version of you you would see you used to see in movies of like the a newsroom, right?

People, you know, everybody, all the reporters sit on a on a on a room and they're like they're pitching their stories. let's talk about this, let's talk about that, right? What's going on we should be talking about? very idealizing, but it's kind of what we do, trying to figure out what are the topics that we should be covering, or I mean we're gonna be covering everything in a way, but which ones we should focus on, which one are the most permanent ones? And then we have to identify, do we have the data to talk about this?

Do we have the partner? Do do our part can our partners provide us the data that would allow us to talk about this intelligently? Right. And so there's a the that initial part is really us making sure the the partners are in line. People do do does everybody want to come back, contribute again? Do we need to reach out to new folks? And and then to to talk to them, engaging with them, and giving them kind of a deadline. so I I need your data like by the first of October.

Sorry, first of November, because our year runs through October to make sure we have time to read, to to to analyze and process the data, right? But let me give you an example, right? You're talking about Hugging Face. in all this like agentic attack, HubHub and and all of those things, even the open claw discussion before, which was a little bit sillier, but there was already a lot of conversations there, right?

Mehul 17:08.013

Yeah.

Alex Pinto 17:12.702

We are we're now engaging companies who specialize in kind of like age agentic security or guardrail development or harness development, because those are the folks that are gonna have assemblance of data which allow us to talk again of this. Okay, guys, y I know you're hearing about all these things, but this is what's really happening. This is what we really know, right? And and and that kind of deal. So this is a constant, right? As things get crazier and worse, right, we have to figure out

Mehul 17:31.309

Mm.

Alex Pinto 17:42.04

Okay, how do we talk about those new things that are showing up? And so by November, sorry, go ahead. Yeah, so by November, December, we are putting the data together, getting the data for the contributors, you know, putting it in a format we can analyze, you know, running our automation, analyzing the data, doing the best we can. And we are writing throughout January and February, right? And so go ahead.

Mehul 17:45.557

And how much? No, no, no, go sorry, finish the talk.

Mehul 17:54.613

Locked in.

Mehul 18:08.267

And I'm I'm and I'm curious like how much independence do you have? Like, you know, my senses, you know, with all this fun and joyful vibe that you have with the with the report, but the report essentially is associated with Verizon, and Verizon is a very uptight business, serious business, red and black, right? So I'm curious like how much independent how much independence do you get? Sorry, I didn't miss that, but

Alex Pinto 18:26.562

Did you see the the doctor evil?

No, I did you see the Doctor Evil ad they had recently.

Mehul 18:36.683

No, no, no that's I'm not saying Dr. Evil, I'm not saying any negative connotations. All I'm saying is Verizon is a very uptight business, right? You don't associate fun with Verizon, but the report itself, even though it is a on a serious topic, it is very it is a fun read. It is a fun, joyful read. And so I'm curious, somebody at Verizon said, You guys let these guys lose. They let them let Alex cook, right? I mean that's not I mean, seems like that's the at least for reading the report, the vibe is they let you let

Let the people who are writing the report do the job that the best job they can. And I'm curious how much independence do you have as you're writing through the report?

Alex Pinto 19:14.231

I would say

Absolute. I mean, it that's not true, right? I know there are things I can't write about, right? Because they potentially would be, you know, I don't know. I I'm no don't necessarily need to go into that, right? Well, you know, I mean within okay, this is this is a professional publication. Let's start there, right? But from there, from that baseline, right, we have the freedom to pursue any topic, any research.

Any partner that we want, that we deem will be interesting for the audience, will be something that will drive the understanding of the industry forward, right? So there's no input from Verizon around what we should be writing about, right? Which again in many ways has been I mean you you can imagine how many complaints I've received over the years around why don't you write more about phones?

Guys, there's nothing to say about phones. when there is something to say about phones, I'll s I'll say it. I'll I'll mention it, right? But they but but it it's very much like you said. It's like they they trust the process. They trust that the output that my team is gonna put out is going to be exactly what's needed, right? And and and ver I I think more importantly than that, it's not so much it's not so much

a trust on on on me or my team, but it's a trust on what the ver the DBIR is. As in Verizon this is something that has become very clear to me as I engage as as I engage with like, you know, very senior leadership in Verizon. Like we understand our responsibility and our duty in putting something like this out. Right? We want this to be absolutely as independent and clear and helpful

Mehul 20:53.165

Mm.

Alex Pinto 21:16.17

as possible, right? We understand this is part and the the DBIR is part of what Verizon Business is. It has been around almost as long as Verizon Business has been around, right? And so we understand this this this responsibility and we understand that the the way that I lead things, the way that my team drives the report is really the way to achieve the objectives that we we set out to do. So I mean again I can't write

Anything that I want. Of course, legal reviews it, right? And marketing sometimes complains, but I usually don't listen to them. but we

Mehul 21:56.224

We'll we'll cut that out from the podcast. We'll cut that out from the podcast.

Alex Pinto 21:59.232

No, no, it's it's fine. They they know they know they know how the relationship works. They I love them. I i they know I can't do this without them. I can do this without a lot of people. And but at the end it's one of those things. They know the results they speak for themselves, right? If that makes sense.

Mehul 22:12.589

And you know, you you you stu when you started the interview you said the initial report started with just the Verizon DBI report vi Verizon data. Then yeah, the and then the and then the Secret Service got involved, a few other vendors involved, and now it is like a giant ball of hair. There are hundreds of vendors. I'm curious how many vendors do you deal with? I mean, especially with this November first deadline that comes up, right? How many vendors do you send out the request for?

Alex Pinto 22:21.72

Those are data, yeah.

Mehul 22:41.771

What's the what's the scope? How many vendors get in get involved? And my follow-up question to that is you know, this is a moment of pride for a lot of vendors to be associated with the DBIR report. but you being independent, or at least you know, the way you have to be independent, you cannot attribute some of these things to the vendors. Well, you know, this we've got this data from this vendor, so now then the that vendor goes to out and markets out. Look.

because of our data, whereas N D P I or got X, Y, and Z. So I'm curious, like first question is how many vendors are involved and what is the process around, you know, collecting the data, attributing the data and so on.

Alex Pinto 23:22.306

So it's over a hundred now, right? And it has we've been like getting close to a hundred for a few years now. We always have like I would say maybe a ten percent, ten to fifteen percent like net new partners every year, but then we also have like a ten to fifteen percent churn, right? Some folks they are not able to to contribute anymore. That's they have some sort of like reorg, like i I mean, especially recently, like

Mehul 23:38.21

Mm.

Alex Pinto 23:51.926

lot of different layoffs and sort of different companies. It's not uncommon that everybody we talked to is not there anymore and we struggle to find a new contact. But eventually we it we're able to catch up in a year or two. But these sorts of things happen, right? and and but again it's a lot of people, a lot of different types of data, right? Part of the difficulty in putting the report together is really like making sure we can make sense of all of that, making sure we

We can analyze each data specifically. But the attribution piece is interesting, right? There's a couple of things we have to be to be aware of. First of all, of course we we clearly identify all the partners, right? And they have the they are they they're cited, they have their logos, right? And then we we frequently do like webinars with them, we we we help them, I mean, they're a part of it as well, right? They help promote it. We we try to help give them a a little back to them as well. But

so we really try not to attribute specific research to specific partners for a couple of reasons. First of all, we we want to make sure that if we're talking about a specific topic, we have more than one vendor that can provide a desk that type of data for us. And and not only that gives us get a better

understanding. okay. This is this is not just a very a biased view. Doesn't matter how big the company is, right? If you get two, three, the view is gonna be better. The the understanding is going to be broader. And so every single section it's like, there's like this paragraph here I wrote, there's like six different companies that send data in. You know what I mean? It's all meshed up together. It's all combined, it's all analyzed. And we are very clear on to not attribute

which company gave us which piece of data. Right. It's already anonymized what we get. So we know who we know the we know the company, the the the the partner that gave us the data, but we don't know who kind of the victims are or or or their customers are. But we try to to to mix it even more because you know yeah this is an incident from an airline in that region of the world

Mehul 25:59.329

Mm.

Alex Pinto 26:14.228

which uses this vulnerability management company, you can probably figure out who it is. Right. So we try to the less the less clues we can give, we do. But it is so the there's a couple of exceptions, right? exception number one is we usually attribu we sometimes attribute by their re by their request like law enforcement, government and non profit.

Mehul 26:19.413

Yeah.

Alex Pinto 26:44.256

Right. And so we usually invite those folks to to to have an like an opinion piece, even an op ed or something like that. So for instance Secret Service, they have they they have a a place, every single report as a kind of a thank you, right? They they they can put a section there and they can you know, they have an appendix where they talk about what's top of their mind, what they're doing, right? And so we do that with with usually governmental and

and law enforcement agencies around the world, right? So the rare occasion where we we specifically cite a partner is when it was no this was a joint research we did with them. And it's something that you know we could only do with them, they could only do with us. And usually the agreement that we have is that okay we'll publish at the same time or close to each other as the DAB

Mehul 27:28.276

I see.

Alex Pinto 27:42.316

DBIR comes out, we, you know, you publish your ver version of the research. So we did, for instance, this year, this past year we did this with Anthropic, right? Because it w again, it was data the only day could have, right? It's very, very precise. It was something they were thinking of researching independently, right? And we worked together, we, we, we kind of augmented their their view on what they should be reporting or not, and we kind of sp

kind of split up. Okay, I can talk about this part, you can talk about that part. And we kind of published, co-published, so to speak, right? But we felt it was important enough for something to be on the DBIR because the D B I R has this again, because of the the the we try to make it easy to read, we try to make it accessible, right? It really has a kind of it it kind of breaks silos very aggressively, right?

Sometimes it depending no matter where you work in security, sometimes you can you're kind of very blindfolded on, yeah, I I this is only the part that I understand. But it gives a lot of awareness to about other different parts of security. So it really helps break the silos and and and quote unquote popularize. I know it's it's a we're still a very niche community in cybersecurity, but within cybersecurity helps popularize a concept or or or or a specific message or or a specific type of research, right?

Mehul 28:48.619

Yeah.

Mehul 28:57.228

Yeah.

Mehul 29:06.762

And when you write when you write these when you write these reports, do you have any fun stories about, you know, writing these stories where you go down this rabbit hole and then i it's too much even for you? Like there are certain topics like, you know, I don't know. I think there was this about fishing, you know, there you there was like way too many jokes on fishing, or maybe the Taylor Swifty. There was something about Swifties in one of these reports. I'm curious, like do you have any fun stories writing the the DBI report?

Alex Pinto 29:38.68

So yeah, we try to make it fun, right? And we definitely encourage we're we're we are definitely encourage each other, right, to to try to make the sections funny, right? And so it it i it really depends on the year, really depends on how much time we have to write, honestly. But we're able to kinda spruce it up, right? There was a whole there was a whole section on vulnerability management a year or two.

Mehul 29:49.802

Yeah.

Alex Pinto 30:06.53

that I put a whole framing around sisyphus and absurdism as a philosophy because of vulnerability managers, you're just rolling the boulder up and and it's falling back down again every time. Right. There was this Taylor Swift section and it was a vulnerability management as well. I usually write the vulnerability management so when I try to try to make it interesting. But because it was the first time vulnerability was started to grow and we're like we're we're entering the vulnerability era, right? And so the whole thing was like Taylor Swift

Mehul 30:35.016

The erasure, the the

Alex Pinto 30:35.96

Song tit yes, song titles puns, the whole thing, right? And like you know we knew we knew it was trouble when the CV showed up and I don't know, I don't remember all the jokes, but we had a lot, right? and again, look, look, you you you you I mean you do you you do the podcast, you do social media work as well, you know, right? It's never the insightful thing that gets the likes, it's the joke that gets the likes, right?

Mehul 31:03.562

Yeah, yeah, yeah. Yeah.

Alex Pinto 31:04.32

And so people reach out to me to this day, not about the findings that we had there, but like, I saw that you did a table swift thing there. If it helps people read, right?

Mehul 31:10.604

Talking about talking about vulnerability. Yeah, then then go for it. Talking, you know, talk let's switch topics. Not even switch topics, but talking about vulnerability management and vulnerabilities. Let's talk about some of the key takeaways from the 2026 report. And the thing that was surprising to me, not surprising in in any sense, in the sense that this has always been the top three or top five issues, but in this year.

Vulnerability exploitation was number one vector to compromise systems. And the th the thing that I found even more surprising, and you know, of after all these talks around prioritization and using sysakev and other metrics, the thing that was surprising to me was the only 26% of the sysakev vulnerabilities were getting prioritized. I mean, exploitation was bad enough, but even like the

Alex Pinto 31:47.33

Yeah.

Mehul 32:07.124

Sisa Cave vulnerabilities were not getting prioritized. I mean, so what else do you expect? You will get exploited. If you're not patching the SISA caves, then you know, Lord help you.

Alex Pinto 32:16.664

So it's it's it's worse than that. They are being prioritized and still all that's managed to get done is 26%. Right. We we didn't we didn't wanna we didn't wanna model like no, let's cut straight to the chase, like CZACAV. No one in their right mind would argue that you shouldn't be looking at those to patch. Exactly. Right. I'm not not not trying to split hairs here. yeah, that was that informational thing. Nobody care, nobody care, nobody can get to that.

Mehul 32:27.566

Mehul (32:36.916) This should not be done. Exactly.

Alex Pinto 32:46.498

There's not enough time. But the ones you undoubtedly have to work on, right? Even those, right, the the kind of the fully patched rate is is surprisingly small, right? And it went down, right? One of the findings was that it was thirty-eight percent from from our reporting on the twenty twenty fifty BIR, twenty twenty-five D BIR, and it's now twenty-six, right? Again, the here are the caveats, right? So we

The numbers don't sh doesn't change that much, right, if you do it on on a different if you're more lenient. But we were looking at fully, fully remediated. So for C V E, let's say you have ten instances of the vulnerability. Did you patch all ten? Right? If you patch nine, you don't get credit for it. Only if you patched the full ten.

There are legitimate reasons why, I'm not gonna patch this one because it's actually like a test instance. We just happen to have it on the vulnerability management thing, right? But it's kind of a a risk you know, registry nuance that we're unable to unable to capture in in bulk, right? And at the end of the day, you know, the the attackers don't care about your risk acceptance policies as well, right? If the thing is vulnerable, it it there's there's risk.

Mehul 34:04.15

They just want to get in. They just want to get in and they'll find whichever one maybe lets them get in, they'll they'll figure it out.

Alex Pinto 34:06.082

Exactly. Right? playing play yeah, you're playing chess with a pigeon, right? It just hops to the board, you know, kicks all the pieces and shits all around it, so

Mehul 34:17.872

the second thing I want to talk about is the impact of Gen AI, the impact of Gen AI on the threat landscape. Are you seeing based on the data that you've seen that attackers are using AI native tools for writing exploits, breaking into systems, or is that too early to tell?

Alex Pinto 34:36.36

y de definitely. Definitely, yes. So the thing the thing that we were ch were chasing, and again, please bear in mind, right? this was written in February, those sections, right? It was before mythos or or anything like that. The thing we were hungry for at the time, and we've been trying to do this for a couple of years, is that is their objective proof, right? Because you get anecdotal data, you would get a lot of anecdotal data from even from the frontier labs themselves of

we saw this thing happening and it's super scary, right? But you know, over the years it has become harder to accept those those kinds of reports at face value because no IOCs and all of the all the the Frontier AI companies, they have a vested interest in looking way more impressive than they really are. That's how the investments come in, right? And so at some point we keep okay, what is the raw data? What what is happening, right?

And and so again by talking with Anthropic, right, they said, No, we've actually done the work. We've actually went back and looked at, you know, a year worth of data of terms of services violations. This is how people are using models like ours to augment their cyber attack capability, right? And all of that discussion went was on the back of their November

last year finding about someone came in and actually used it to orchestrate an attack, right? And so the the findings overall is that it's being used, right? All sorts of different techniques are being researched. again, it's and again attack techniques don't capture the whole nuance of what they are able to do, but it's it's a good shorthand. It's a good it's a good way to kind of ground the conversation for security practice, right?

Mehul 36:28.396

But it but my question is my question is it could also be the good guys doing pen testing. Right? I mean it could also be like, you know, Enthropic, they're using Enthropic, but they're pen the the good guys are creating these exploits internally to exploit whatever internal systems they have. Is that well, that is one possibility. I'm curious, how would how would l your reporting or your data sources confirm whether they are seeing evidence of attackers using

Alex Pinto 36:29.129

And correct.

Mehul 36:57.61

the latest tools, maybe it's enthropic, maybe it's open AI, maybe it's like the open source model. Is would you would you have those kinds of signals in the re report? Not maybe not in this year, maybe in the next year or in the future. Is there a pathway for you to know?

Alex Pinto 37:09.176

So the so the the so specifically in this case we are we are relying on anthropics judgment, right? Because again, we don't we have no information about who were who were the accounts, what were the accounts that they were doing that. So my what can I say, the way I understand, the way they explained it to me and and what it looks like from what they presented to us was that we actually

Mehul 37:17.9

Mm-hmm.

Mehul 37:21.516

Yeah, yeah.

Alex Pinto 37:33.694

Looked at these guys with these accounts that were flagging us or trying to do malicious things, and we know these are not paying like enterprise customers. We know these are not, these are like individuals or unra. So there was that definitely was some due diligence on their end. Not that they wouldn't block someone trying to trip the guardrails in a in a in in an enterprise account, but probably what that means is that somebody would pick up the phone, hey, can you please stop doing that? Or do you want to play X amount?

more money so you can have the fully, you know, released one or something to their regard. Yeah. Hey, yeah, yeah, yeah, no, we have one for you. It's just cost four times more. We can be happy to Exactly.

Mehul 38:07.54

That's probably the reason they would call it. That's probably the like more likely new.

We have Fable Six on the we have Fable Six on the line for you. Would you like to have a chat?

Alex Pinto 38:19.52

Yes. boy. You know, you think about models hacking themselves or coding themselves, imagine the models selling themselves. Now that's real hell. That's really where, you know, we're gonna have to draw the line. But no, I do trust their yeah. Yeah. So at the end of the day we have to trust the the kind of dare, kinda know your customer process on something like that, right? But

Mehul 38:30.848

Yeah. yeah, we can definitely help you with exploit research. Yeah, sorry, go ahead.

Alex Pinto 38:49.292

I don't know. I don't even know how reliable this data is going to be. even if we try to do the same thing next year with the kind of potential shift to open you know open weight models and things of that nature. It's very hard to tell, right? And my the the general consensus of the AI lab folks is that any abuse activity that you see in the frontier models is actually fairly representative.

of what we would see or what we're going to see on open weight models for two reasons. Because it doesn't matter if you have a model, kind of you you have like a kind of Mac Mini, you know, running under your desk, right? That's where you you do your stuff. Yes. And so yeah. And so but they are always testing the frontier capabilities because they want to know you know where everybody else is. Everybody's testing each other all the time, right?

Mehul 39:29.546

Mac Studio. Mac Studios are very popular now. Mac Studios are paranoid.

Mm-hmm.

Mehul 39:45.897

Mm-hmm. Mm-hmm.

Alex Pinto 39:46.648

Because that's one window. And two, because of kind of distillation attacks, right? People will continue to hammer the frontier models because they'll try to get something out that they can use for the kind of the open weight stuff. So even as attacks move to open weights, you know, I sh I share their belief that the data from AI Frontier policy violation and I frontier models will still be representative of what they're being used for for attacks. But

Honestly, between you and me and all the hundreds of people listening to the podcast, I think this is gonna thousands, sorry, apologies. Tens of thousands. we I think we're gonna I think next year we're not even gonna talking be talking about that. As in it's it's it's already things are moving so fast, this is almost seeming like this is gonna be sound like business as usual next year, right? In what?

Mehul 40:21.332

Well it's thousands. It's thousands. It's thousands.

Alex Pinto 40:44.432

It's been what a a year since kind of like Claude Code be got good, quote unquote. A year, right? Nobody I mean, you know, a almost everybody is using some sort of assistance now, and this is just normal, right? It's something that you know, people have learned how to use those tools and people have learned how to to leverage them, you know what I mean?

Mehul 41:09.494

Curious for the next year's report, are you actively sourcing data from the open source models and the frontier models? Like, you know, you have anthropic relationship for 2026, but then you know, actively looking for evidence of exploitation or malicious activity with your models. Like, you know, do you go to Kimi? Hey, can you do you have any data? Are you is that actively are you in that three-month phase where you are like figuring out what to do with the

Alex Pinto 41:33.28

Absolutely. No, very much so. Very much so. Again, we cannot so we cannot see what people are doing in open weed models, right? Because they're they're they're hosting it locally, right? It's the same pro but

Mehul 41:44.246

No, but they're still you could still reach out to Google. You could still reach out to the ho hosting well, maybe not. Not maybe you don't you don't have that level of insight. Yeah.

Alex Pinto 41:51.884

No, yeah, I mean i i if it's hosted, it's easier, right? Th someone holds the key. Right? As long as they're willing to talk about like policy violations, they have some potentially have some insights that they can share, right? I think one of the and again we we were mentioning the hugging face thing, which is the big thing that's going on right now. One of the things that I'm super interested in it in in that whole story is that, you know.

if given that this is and it really seems to be, right, a confirmed public case of you know an autonomous agent doing these sorts of attacks, can we use that as a blueprint to identifying similar attacks like those from the perspective of the victim, right? Because as I was telling you before,

Our our our work on twenty twenty five, twenty twenty four was the victims were unable to tell, right? Is someone using malware against me that had been an AI assistant in any way? But it looks like if it's kind of like an autonomous agent thing, because these things are just so darn noisy and very much their models operandi is throwing spaghetti at the wall, right? it will be fairly at least in for some time, it will be fairly easy to identify.

yeah, this was an agent here, maybe running on an open model somewhere that was trying to get inside. Who knows how long that's gonna roll that that's gonna hold, and then these things will learn to actually get a little bit more stealthy. But as of now, right, being hacked by by an autonomous agent, it's like you know, you're in Vegas and you're just playing a loss a lot machine, right? And it just tries absolutely everything. If you try a hundred thousand times, you hit the jackpot, right?

Mehul 43:21.301

Mm.

Alex Pinto 43:46.028

You lost a lot of money on tokens, right? Or on compute. But eventually you hit the jackpot. Anyway, the the tokens always win. The house always win. that's the that's the the the thing.

Mehul 43:48.616

Yeah.

But at least we got in. At least we got in one time. and then the house. and the last big or at least one of the big takeaways for me was like the use of shadow AI. I think the report it says sixty seven percent of the users are it's like non approved or y are using in you know in their

on their corporate systems. Do you see this on the rise going forward as well? The use of shadow AI or anything it is becomes approved. Now everyone go use these models, do whatever you want to do. We it's not something we can stop anymore.

Alex Pinto 44:26.816

Yes, so

Alex Pinto 44:33.844

Yeah, it's it's the the pro so this is a story that has happened a thousand it it always happened again and again and again, right? And you know, ever since the internet came to offices, people have found ways to send files, you know, away from the office. And it's really the the thing that gets people kind of like unprepared is really the the kind of the staggering velocity in in which these things are impossible.

Because the key number there on that section is not that it like sixty-seven percent. I mean, it's bad, don't get me wrong. Sixty-seven percent of users and like it's corporate machines, right? They're going to using personal accounts on those kind of AI tools and things of the sort. So clearly not organization sanctioned, right? Because otherwise they would be paying for it, they'll have a contract somewhere.

Right? Maybe a zero retention policy, all the good stuff that you want. None of that. This is a personal account. The the problem is not so that's what that number sixty-seven was seventy-two percent before, right? It actually got better if you think about it. But it was fifteen percent of users who were kind of doing the access, right? By it we're doing like did they did they go to one of these things one every two weeks? Very conservative, right? And then this year.

Threefold, forty-five percent. Right? That's the growth. Right? Three times more people doing bad stuff. sorry, I shouldn't say that. Misguided. Yes. Yeah, the the math doesn't math. It's still bad. It's still bad. Right? But but that's kind of the thing. That's the staggering thing. Again, every single AI story is a story about scale.

Mehul 46:04.214

inter.

But it but it's less than the seventy but five percent less overall. There's three X more people, but five percent less overall. It is it is still

Alex Pinto 46:28.49

Is a story about acceleration, right? And so we see something that didn't exist three years ago, four years ago, right? Is now number three most likely way that confidential data will get like non-maliciously exfiltrated by your environment. Only loses to file sharing services in the internet. I just uploaded my contract to Dropbox or something like that. Or and

Personal webmail, right? yeah, I'm just gonna send myself this this thing via email here, so I can review it at home. These two are like, you know, his classics, historical, right? seminal ways of extra trading data.

Mehul 47:13.555

Even even even the even the presidents have done it. It's not just the common men. Even the presidents have done it. And no one has gone to jail. No one has gone to jail.

Alex Pinto 47:25.164

Yeah, sometimes it's just a ravioli recipe, okay? It's not that a big d not that much of a big deal.

Mehul 47:30.043

Or or it is what is it, the yoga instructions. Or it is the you know, the yoga classes, you know, if you if you go back to the Hillary Clinton emails, it was what? just the yoga instructions, right?

Alex Pinto 47:35.829

Yeah.

Alex Pinto 47:39.714

Exactly. Exactly.

So but but that's the thing. And Shadowy Eye is number three now, right? Out of the blue, no the the the the the no the gr the green horse coming out from the outside just overtakes everybody, you know?

Mehul 47:57.286

and Alex, you've been doing this for eight, six or eight years. and you've probably seen a lot of trends come in, go out. Like, you know, based on your point of view, what are some of the trends that you've seen in you know in your time overall? Any big changes that you've seen working on the DBR report for all these years? Anything that stands out to you?

Alex Pinto 48:21.576

not so much it's not so much change, right? But you learn to everything in cyber is an overnight success. as in now for the first time in 19 years, the vulnerability exploitation is the number one factor. Well, we've been tracking it for four years going up, right? We were just trying to see, okay, is it gonna be this year, that year, right? That was our the bet we were taking at the office.

Mehul 48:41.609

Yeah, he's just got a

Mehul 48:46.513

It is a four year it is a four year overnight success. It is a four year overnight success.

Alex Pinto 48:50.57

Exactly. Exactly. So but there's one thing that's always been true, right? And kind of I haven't been been disproven as far as like what's the biggest trend, right? If you're trying to predict, you know, what's going to happen, you really have to look at the economics of it. Because the attackers will always it it's always the path of least resistance. What is the easiest way for a breach to happen?

Right. And I think it's concerning, right, that the kind of the shift on the vulnerability thing, what what it's actually telling us like it's now easier. The path of leaf least resistance is vulnerability exploitation as opposed to getting credentials, even though there is a huge infrastructure in the dark web for reselling credentials and buying credentials and all of that. That thing was they're cheap.

Super easy, right? But now for getting in the first way, vulnerability seems to be the path of least resistance. So that's scary.

Mehul 49:57.61

And it's easier. And it's just getting easier from here. It's not getting any harder. It's just gonna get easier from here.

Alex Pinto 50:01.346

Correct. Correct. And the second thing is what are the objectives, right? The objectives are always gonna be what gives them more money, right? And so it's the whole story about ransomware. Why is why does ransomware doesn't go away, right? It's because it is by far the most you know, easiest way for you to monetize a breach, right? You know, in the old days you had to go into you had to look, do they have credit card data here?

Mehul 50:25.515

Yeah.

Alex Pinto 50:31.616

You know, can I resell this credit card data? Or do they have conf what what am I gonna do with their confidential data? No one's gonna wanna buy their confidential data. How am I gonna do this? You know, how am I gonna get money from this? Right? And so ransomware is incredibly efficient. The only thing that's more efficient financially wise than deploying ransomware is breaking into cryptocurrency exchanges, right? That you cannot beat, but there are not that many of them, right?

Mehul 50:55.347

Yeah. Right.

Alex Pinto 51:00.756

If if for some reason you happen across a credential or you happen across, you know, a breach or something, someone that's not a cryptocurrency exchange, the best you can do is something like ransomware. So the other thing that's fairly easy and low hanging fruit is is just fraud, like plain old financial fraud through social engineering and things of that nature. You see that play a lot on the consumer space because obviously they don't have anything for the ransomware doesn't really scale.

at that level. It's too much work for too little pay, right? Which is also another fascinating thing, right? How much do people charge on ransomware? They charge as much as they think the the victim is going to pay. And so as they went downstream, right? And just like, let's just breach anyone, they'll just they're not gonna ask a million dollars from the mum and pop shop. They're gonna say, give me five hundred dollars, right? Because because that's it they know that the the people are not gonna think about you don't want people to think about it if they want to pay or not. But anyway.

Mehul 51:51.465

Fine and bug dynamic.

Alex Pinto 51:58.732

That's a s that's a different story. So it's always about the economics. It's it's a business at the end of the day, right? And so what's the easy how do I minimize my my costs, right? And how do I maximize my wins? It's always that.

Mehul 52:00.488

And

Mehul 52:11.091

Yeah. It's an ROI discussion for the hackers too, or the attackers too. Like what's my request what is my ROI?

Alex Pinto 52:14.27

One hundred percent man. Nobody everybody has a boss, everybody has a budget. It's you know, no escape. There's no escape.

Mehul 52:22.499

Alex, do you after doing these reports for so many years, do you engage in any predictions? Do you do predictions and like have your prophecies ever been true? Like have you been have you been given any gift of have been given the because yeah, have you been any given any gift of prophecy? Or is it a curse of prophecy?

Alex Pinto 52:33.794

No, it's it's

Alex Pinto 52:41.792

No, it it is it it look, it's absolutely a nasty business, the business of prediction, right? I actually I had a year that like Verizon Verizon like Verizon marketing, hey don't you wanna watch like predictions for next year? Like no, you you g I'm not. I'm not gonna put my hand in that because I know it's just like I'm just gonna make a fool of myself. But because so one of the jokes we have on the report, like internal jokes, right?

Is that every time you make a claim on the report that yeah, it looks like it's gonna be like this from now on, the opposite happens. And the opposite happens like immediately, as in we are right we finish writing the report, we're going through revisions, and it's like a few weeks before launch, and then the trend gets disproven very decisively. And then I have to go back, add a footnote, like

No, we still keep the text where we predicted, but within like, yeah, as usual, as we make a statement like that, right, this thing just happened, it's obviously not gonna be like that, etc. etcetera, et cetera. And so it was very surprising this year because again, it it's one of those things, right? If you if you pay attention to a trend long enough, you can start to kinda guess where these things are going, but yeah.

Mehul 53:59.187

Yeah, you can see around the corner. You can see what is coming around the corner.

Alex Pinto 54:02.73

The two headlines we had were exploitation being a bigger problem and getting worse and we having a b worse efficiency in patching and the AI augmented attacks, right? And those two topics they converged very aggressively together with the mythos discussion in April. And again, we wrote in February. And so for the first time in a very long time, I don't remember the last time I had to do something like this, I actually had to go back to the report to say.

yeah, we were more right than we thought we were. We are aware this thing happened. Here are some other recommendations and things of the sort, right? So prediction, my friend, is is you know, you're just gambling. It's just you just put everything on black, put everything on red. Every time you try to predict predict something, right? Sometimes we're wrong, sometimes we're right. But the trends don't move very, they don't move that much, right? It's only when you're trying to

Mehul 54:56.071

Alex, you need to you need to you need to start something on polymarket. The next time, you know, you start

Alex Pinto 55:01.45

I know, I know, but the only thing I can bet, the only thing I can do is like real insider trading. Is the DBR gonna talk about this thing, right? I'm gonna create a fake account, right? I'm gonna call my like third cousin removed. My third cousin removed in another country. Hey, create an account for me. I'm gonna tell you what to bet on. You know, that's that's that's the only way.

Mehul 55:11.563

Definitely not.

Mehul 55:21.631

Bet like a million dollars. Bet like a million dollars on this one.

Alex Pinto 55:27.16

I'm sure nobody cares. I'm I'm gonna be the only person batting against myself and

Mehul 55:30.665

And you win. And you win the house the the house wins.

Alex Pinto 55:35.958

Yeah, it's one to one, right? Only one person bet and so you you get your money back. Congratulate Well, look, it's a better outcome than the vast majority of people, you know, playing around with those things, so

Mehul 55:48.357

a last question, or last topic, you know, you go through this process for months. Like it starts in maybe November, maybe even early November, and then it gets to the launch day. What is I'm always curious, what is launch day like for DBIR, for somebody who's been invested for such a long time, you know, or months for the report to come out. What does launch day feel like? How is the day plus one feel like once the report goes out? And you know, how do you take the feedback where the comments come in?

There are naysayers and yeah. Like how does the I'm curious like what is like the the dynamics of that day and then maybe two or three days plus or minus after launch?

Alex Pinto 56:18.998

Yeah, it's

Alex Pinto 56:29.3

it's just just like obsessively refreshing social media, I guess. Right. And we usually have a lot of stuff we do in launch date. We usually still have like media interviews and we have there's always a webinar we put together. So we there there's actually quote unquote work to do, right? But we're always very curious about what the the reception is. And it's fairly it

Mehul 56:52.722

And what is the primary way of getting the feedback? Is it mostly emails, like emails coming in, or are there other ways?

Alex Pinto 56:58.05

So so there there's some there's some so we get a lot of like social media stuff, right? People talking about what they think. I'm gonna be honest, it was way more interesting to read against those like two or three years ago because almost everything now you go on LinkedIn is someone just ran the thing through an LM and this is my summary. I read it so you didn't have to read it, they didn't read it. And they they put the things that the LLM I I so I had a great one.

Mehul 57:25.714

You know the thing?

Alex Pinto 57:27.158

I have a great one. I bring one for you. the there were people on the day of the launch, like, here's my summary of the 2026 D V I R. But the whatever thing, ChatGPT, whatever they used, they hadn't updated yet. So they published, here's my summary of the 2026 D V I R, and then they put the 2025 talking points. And I'm like, guys, I've never been so you know, so shocked that that people really don't read what the thing puts out.

Because, you know, they clearly didn't care any any at all about what the the actual findings were. They they just got whatever the thing spit out and put it, it was completely wrong, right? It was more interesting when people wrote their own opinions as opposed to, you know, just outsourcing their thinking to to an L L but we still do get a lot of very thoughtful and interesting comments and things of that nature.

Mehul 58:18.974

I mean the thing I find surprising is people don't reach out to more people like you, the authors, rather than the commenter. The thing I find like super surprising is like if you really wanted to get the insights of the DBIR, how about just talk to the authors? And not not listen to these commentators who are essentially just paraphrasing what Chat GPD said. Like, you know, go talk to Alex. Alex probably has spent six months working on it.

Alex Pinto 58:36.376

Mm-hmm.

Mehul 58:49.13

he probably would provide you with better insights that you can actually quote him on. I'm curious, like do you feel a sense of not jealousy, but like, dude, I am sitting right here. Ask me. I can just ask me. I would I can give you better insights than this random commentator who thinks that's you know who who had a comment about the D V IR.

Alex Pinto 59:02.914

Look.

Yeah.

Alex Pinto 59:11.416

So I I mean the short answer is no, right? The short answer is you know I personally find it very rewarding to have people talk about it, right? It this is what we do this for, right? So we wanna we we wanna the best we can like kick start this course, right?

But I I wish it wasn't just the same people posting the same output from an L L I wish someone posted something. And we have some good examples l around launch of like someone starting a discussion and then like there's like literally a hundred comments, right? People talking to each other and sharing their opinions. This is the kind of thing we live for. I don't care if it's wasn't on my account, right? you know, my reach I in honestly I don't have the temperament for for social media at all, right? I I make a joke or two, some

Mehul 59:52.446

Yeah.

Alex Pinto (01:00:00.63) You know, but I I'm not gonna be engaging there, you know. so I I'm glad there are people that do that and they're able to push the message forward, provide their opinion. And again, it's it's an opinion. Our ours is also an opinion, right? It we fundament it the best we can, but we really wanna drive discussion forward. We wanna drive awareness forward, right? This is really what it is for. Having said that, I have made that joke once or twice before, like, hey journalists, if you get a peach from

Mehul (01:00:03.444) Yeah.

Alex Pinto (01:00:29.206) page from X, Y, and Z on like they want to share with you the views of the about what they read on the D B I R. We're right here. We wrote it. I'm pretty sure my opinion is gonna be much better and much more accurate than, you know, whatever that was. So so keep keep that in mind. But but anyway. Now but we do a lot of we do a lot of outreach as well to like content creators and and and and media folks and

Mehul (01:00:41.872) The chat GPT version of this commentator.

Alex Pinto (01:00:58.092) Again, for us it's important. It's not it's not so much it's not really an ego thing, right? Our job is to make the report successful, accurate, helpful, right? And so if people are talking about it, people they're you know, yes, ending it, right? And this is what they are found and this is my experience. That's exactly what we're going for.

Mehul (01:01:21.372) Alex, that's a good place to end. super grateful for you to coming on Noise to Signal podcast. this is the this has been an amazing interview. Thank you.

Alex Pinto (01:01:32.012) No, really appreciate it, man. Had a lot of fun.