Cyber Security District
The interview podcast for cyber security professionals and for those who aspire to become one. We interview industry experts to get to know the latest trends, real life war stories and everything you need to know about this exciting industry.
The interview podcast for cyber security professionals and for those who aspire to become one. We interview industry experts to get to know the latest trends, real life war stories and everything you need to know about this exciting industry.
Episodes

Jul 17, 2026
Jul 17, 2026
31 min
What if your infrastructure was built secure from minute one and stayed that way?
In this special one year anniversary episode of Cyber Security District, host Jeroen Prinse sits back down with Mahdi Abdulrazak (CEO) and Kim van Lavieren (CTO) of Dawnguard, a security automation platform that turns approved security architecture directly into deployable cloud infrastructure as code.
One year in, having just closed a pre-seed round and raised €6.3 million in total funding and opening a new office in New York, Dawnguard is making a bold bet: that the only real answer to modern cyber threats isn't better detection or faster patching, it's building systems that are resilient by design from the very start.
Mahdi and Kim have both led security teams inside large organisations and lived through the same recurring nightmare: architecture locked in too early, security reviews arriving too late and a list of 50 findings that nobody has time to fix before the product ships. Dawnguard was built to break that cycle, with a collaborative canvas that lets teams design, validate and deploy secure infrastructure in minutes, with continuous drift detection to make sure it stays that way.
One year on, we look back at how far that idea has come and what's next as the company expands.
Key Takeaways:
You cannot patch your way out of agentic AI attacks, the only answer is building more resilient systems from the start
The hardest translation in security is from policy to architecture, ambiguity and contradictions there cascade into every layer below
Context is the missing ingredient in most security tooling: secure or insecure is a binary lens that doesn’t reflect reality
Drift detection only works when you know what was approved in the first place, that’s the advantage of integrating into the design lifecycle
Security decisions still belong to the business and engineers, Dawnguard removes the friction, not the ownership
The shift from protection to resilience is already happening: it’s not if you get breached, it’s how contained the blast radius is
European founders can compete, but capital conviction from investors matters as much as capital volume
Timestamps:
00:00 – Introduction
00:15 – Meet Dawnguard
00:48 – One year in: what proved Dawnguard was solving a real problem
01:30 – How customers are using the platform today: discover, design, deploy, monitor
03:20 – The shift-left moment: when architecture gets locked in and it’s already too late
05:15 – why organisations overestimate their resiliency requirements
06:15 – What Snyk, OPA and Sentinel leave unresolved
08:30 – Guardrails vs. findings: preventing vulnerabilities instead of just reporting them
09:30 – Policy to architecture to code to production: where is the hardest translation?
11:00 – The Mythos era: agentic AI and why patching is a losing strategy
12:50 – The shift from protection to resilience
15:00 – Blast radius reduction and the holistic trade-off view Dawnguard provides
16:45 – Drift detection: how Dawnguard tells a legitimate change from a malicious one
18:20 – Prompting redesigns for cost, sustainability, and resilience
20:00 – Bringing guardrails into the developer IDE in real time
22:25 – Who owns the security decision?
25:45 – European digital sovereignty: what it concretely means for Dawnguard
27:55 – Raising €6.3 million from European funds in year one
29:10 – What excites Mahdi and Kim most about the road ahead
30:40 – Final message: what CISOs should be doing differently a year from now
Connect with the guests:
Mahdi Abdulrazak: https://www.linkedin.com/in/mahdiabdulrazak/
Kim van Lavieren: https://www.linkedin.com/in/kim-v-0645931b4/
Website: https://www.dawnguard.io/
Follow Cyber Security District:
Jeroen Prinse on LinkedIn: https://www.linkedin.com/in/jprinse/
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
Jul 17, 2026
31 min

Jun 16, 2026
Jun 16, 2026
54 min
What does it take to build a cybersecurity company not once, but twice from the ground up?
In this episode of Cyber Security District, we sit down with Francisco Nina Rente, one of Portugal's most accomplished cybersecurity entrepreneurs. Francisco started his journey as a teenager tinkering with computers and quickly found his way into ethical hacking and open-source security communities. That curiosity became a career, which then led to a company.
His first venture grew from a university incubator into a 250-person operation delivering services across 22 countries, before being acquired by a global security group. After years scaling that business from the inside and taking on roles as country manager, CTO and board member, Francisco stepped away to build again.
This time, the mission is clearer: help organisations stop just detecting threats and start truly recovering from them. Art Resilia was born out of a conviction that the market was shifting from cybersecurity to cyber resilience, and Francisco positioned the company right at the centre of that shift.
Key Takeaways:
Cyber resilience is about recovery, not just defence
Focus beats opportunity-chasing, especially in the early days of a startup
The Commonwealth of a team always comes before individual interest
Trust-based security communication outlasts fear-based selling every time
Knowledge remains the core differentiator, even in the age of AI
Timestamps:
00:00 – Introduction01:20 – From a family computer to a hacker mindset04:00 – First paid gig: penetration testing for hardware05:30 – Building Portugal's first incident response team at university09:00 – Selling trust, not fear: early media and awareness work11:00 – Scaling to 22 countries and finding the right investors15:30 – The acquisition: joining a global security group20:00 – Growing into CTO and leaving on his own terms22:00 – The idea behind Art Resilia and reading the market shift24:30 – The name: "The Art of Resilience"25:00 – Where Art Resilia stands today: 50 people, 4 countries27:00 – Why the Netherlands and Benelux?28:00 – Lessons from 20 years of building: focus, people, pragmatism33:00 – Culture, remote work, and hiring for values first40:00 – What's next for Art Resilia in 3–5 years43:00 – AI in cybersecurity: tool or transformation?45:30 – Advice for young professionals entering the field52:00 – Final message to CISOs: protect both business confidentiality and individual privacy
Connect with the guest:Francisco Nina Rente: https://www.linkedin.com/in/frente/Website: https://www.artresilia.com
Follow Cyber Security District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
Jun 16, 2026
54 min

May 26, 2026
May 26, 2026
48 min
What if you could clone your best cybersecurity consultant and put them to work on five engagements at once?
In this episode of Cyber Security District, we sit down with Leslie Clement and Erie Berhitu, co-founders of Clember AI, an EU-first, AI-native platform built to automate the repetitive, time-consuming work that holds cybersecurity consultants back. Both Leslie and Erie spent years grinding through the same manual loops at major consultancy firms document analysis, gap assessments, risk reports, roadmaps before deciding enough was enough.
Rather than build another consulting firm or hire more headcount, they built a platform. Clember AI now enables security consultants to run five or more client engagements simultaneously, with consistent, high-quality output every time. And they did it entirely bootstrapped, no VC, no investor pressure, just product-market fit and a clear-eyed vision of where cybersecurity consulting is heading.
In this episode, we explore:
How a company getting hacked on day one of the job launched Leslie’s career in cybersecurity
The year-long frustration that led Erie and Leslie to build Clember AI instead of another consulting firm
Why they chose to stay bootstrapped despite investor interest and why they don’t regret it
How Clember AI automates the full consulting lifecycle: document ingestion, gap analysis, risk translation, and reporting
Why consistency across junior and senior consultants is a bigger deal than most firms admit
The shift from hourly billing to monthly retainers and how Clember keeps consulting firms “interesting” to clients year three and beyond
Their vision: becoming the Datasnipper of cybersecurity consulting
Why embracing AI is non-negotiable for CISOs and why helping early-stage startups matters for the whole industry
Timestamps:
00:00 – Introduction
00:15 – Meet Leslie Clement and Erie Berhitu
01:40 – How Erie got into cybersecurity (and why it wasn’t exactly planned)
02:45 – Leslie’s rough first day: getting hacked with no tech team
04:00 – The shared frustration that sparked Clember AI
06:10 – Why they chose to build a tech firm instead of a consulting firm
08:30 – The first product concept: automating the questionnaire
11:20 – Who Clember AI is actually for: cybersecurity consultancy firms
14:00 – Billable hours vs. scale: how Clember changes the math
17:30 – The shift from hourly billing to monthly retainers and staying interesting in year three
22:00 – Will AI kill traditional consultancy? Leslie and Erie’s take
25:10 – How Clember works: document ingestion, gap analysis, risk translation, roadmaps
29:00 – Consistency across consultant seniority levels
31:30 – Hiring technical talent as non-technical founders
34:00 – Staying bootstrapped despite VC interest and why pivoting was easier without investor pressure
38:30 – What made Clember appealing at an early stage
41:00 – The hiccups: work-life balance, family, and knowing when to step away
44:30 – Gut feeling vs. rational decision-making as founders
48:00 – The vision: Clember as the Datasnipper for cybersecurity consulting
51:30 – What’s next: new markets, sales hires, and scaling customer success
54:00 – Data privacy and security by design inside Clember
57:00 – Final message to CISOs: embrace innovation, and back the startups
Connect with the guests:
Leslie Clement: https://www.linkedin.com/in/leslie-clement/
Erie Berhitu: https://www.linkedin.com/in/eberhitu/
Website: https://www.clember.ai/
Follow Cyber Security District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
May 26, 2026
48 min

May 12, 2026
May 12, 2026
45 min
In this episode of Cyber Security District, we speak with Tom Leijte, founder of Passguard, one of the most exciting emerging cybersecurity companies in the Netherlands. Passguard helps organizations detect when infected devices, stolen credentials, and active sessions show up on criminal marketplaces, giving security teams early visibility before exposure turns into a breach.
Tom shares how his journey started outside of “traditional” cybersecurity, working in private investigations where dark web intelligence was already part of high-stakes screening work. Together with his technical co-founder, he built the capabilities to infiltrate closed criminal forums and surface the kind of forensic-level logs most companies never see until it’s too late.
In this episode, we cover:
Using dark web intelligence for sensitive employee screening
Why “classic” dark web monitoring often gets deprioritized by security teams
The infostealer shift: stolen session tokens, not just leaked passwords
How session theft can bypass MFA and why that changes the game
How criminal marketplaces work (and how trust is built among criminals)
How Passguard infiltrates closed forums using reputation, escrow, and long-term access
Building a European-first solution and partnering with MSSPs / security platforms
Scaling after investment: team growth, ICP clarity, and market expansion
Timestamps:00:00 – Intro00:15 – Meet Tom Leijte and Passguard’s mission00:37 – Early visibility: exposure before it becomes a breach01:22 – Tom’s background in private investigations02:13 – Screening sensitive roles using open-source + dark web sources03:47 – Why dark web intelligence matters for organizations04:39 – How Passguard started (and the co-founder story)05:53 – What surprised Tom most about the dark web06:20 – Data breaches vs data brokers: what ends up for sale07:20 – Discovering infostealers and why they’re different08:17 – Session tokens, MFA bypass, and the “unmanaged endpoint” problem10:01 – What infostealers capture (sessions, access, and more)11:10 – Why SaaS + remote work + BYOD changed attacker economics12:27 – Supplier and branch-office risk: the blind spot organizations miss14:31 – Why classic “dark web monitoring” wasn’t landing in the market15:38 – The Mom Test and learning to run real customer conversations18:08 – Reframing the problem: focusing on infostealer exposure20:38 – How the dark web works (no “bookmark”, reputation, escrow)23:11 – Passguard’s approach: bots, reputation, and long-term infiltration25:55 – Real-world example: infostealers and large-scale government breaches27:37 – What stolen access is worth and how it gets packaged for sale29:19 – Screenshots, persistence, and “always up-to-date” stolen sessions30:05 – Educating customers and turning awareness into action31:03 – What Passguard delivers: evidence, context, and early alerts33:08 – The Snowflake case: old credentials, massive impact36:06 – Scaling after investment: pressure, growth, and coping37:18 – Why Tom chose experienced cyber investors and operators39:43 – Passguard as intelligence inside MSP/MSSP security workflows41:45 – Team expansion and what roles matter most next43:27 – ICP clarity and European market expansion45:27 – Signal message to CISOs: give startups a chance early46:50 – Outro
Connect with the guests:
Tom Leijte: https://www.linkedin.com/in/tom-leijte-01596536/
Website: https://www.passguard.com/
Follow Cybersecurity District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
May 12, 2026
45 min

Apr 28, 2026
Apr 28, 2026
53 min
In this episode of Cyber Security District, we sit down with Julius Muth, co-founder of Revel8, a fast-growing startup tackling one of the most urgent threats in modern cybersecurity: deepfake-powered social engineering.
Julius flew in from Berlin to join us in the Amsterdam studio and breaks down how attackers are already cloning voices, abusing call centers, and using multi-channel manipulation (email, WhatsApp, LinkedIn, video calls) to bypass technical defenses and target employees at scale.
We also get into how Revel8 scaled from early MVPs to large enterprise rollouts, the team’s operator DNA from Celonis, and their goal to build “10 million human firewalls.”
In this episode, we dive into:
Why deepfake voice phishing is exploding via service desks and call centers
The real-world deepfake fraud case that changed everything (25M USD)
How Revel8 personalizes awareness with role-based “playlist” simulations
Why time-to-first-report beats click rate as a security KPI
How Revel8 scaled fast: funding, enterprise rollouts, and culture
Key Takeaways:
Deepfakes turn trust signals (voice, video) into attack surfaces
Context-rich phishing is far more effective than generic campaigns
Awareness works best in short, relevant, continuous moments
Measure reporting behavior and speed, not “gotcha” click rates
Modern threats require modern training across every channel
Timestamps:00:00 – Introduction00:15 – Meet Julius Muth and Revel8’s mission01:20 – Why deepfakes are a serious enterprise risk02:30 – Voice phishing through service desks and call centers04:00 – A real incident example and why it’s “hot” right now04:45 – Founders’ background and the Celonis operator mindset05:40 – Validating the market (100 handwritten letters)07:10 – The deepfake fraud case: 25M USD and what it proved09:20 – Social engineering is leveling up (multi-channel trust)12:00 – The “podcast vote” scam and impersonation patterns14:20 – From MVPs to enterprise: what changed after hiring a senior CTO19:00 – Why traditional awareness training fails23:40 – The “Spotify playlist” model: personalized learning journeys26:00 – Turning real attacks into simulations28:40 – Better KPIs: time-to-first-report and workforce sensors31:10 – Modern payloads and “make the victim execute” tactics34:40 – Scaling growth: team, cold-calling “Champions League,” and GTM41:40 – Advisors, credibility, and enterprise access45:00 – The goal of “10 million human firewalls”46:10 – Why the name Revel8 (and the naming story)48:40 – Hiring profile and what they look for51:40 – Munich office move and what’s next52:35 – Final message to CISOs
Connect with the guest:Julius Muth: https://www.linkedin.com/in/julius-muth/
Revel8: https://www.revel8.ai/
Follow Cyber Security District:Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/Website: https://www.cybersecuritydistrict.com/All channels & newsletter: https://beacons.ai/cybersecuritydistrict
Apr 28, 2026
53 min

Apr 14, 2026
Apr 14, 2026
58 min
Title: Securing the World´s biggest HR Firm | Martijn Nykerk, CISO at Randstad | Cyber Security District
Episode Description:
What does it take to secure a company that manages the careers of millions of people across the globe?
In this episode of Cyber Security District, we sit down with Martijn Nykerk, CISO at Randstad, one of the world’s largest HR and recruitment firms, with over 6,000 branches across 38 countries. Martijn has spent 20 years inside Randstad, growing from running the Dutch telco infrastructure to becoming its first global CISO, building security from the ground up as the company transformed from a federation of local operators into a true multinational.
With an engineering background forged on North Sea gas platforms, Martijn brings a rare perspective to the CISO role: the ability to zoom in and out across technical, process, organizational, and business layers simultaneously. In this conversation, he breaks down what that actually looks like in practice, why social skills matter more than most security professionals think and how to build a security function that people want to work with.
In this episode, we explore:
How Martijn’s career started on a North Sea gas production platform and why safety systems are the original cybersecurity
What it took to build Randstad’s first global security function from scratch
The CISO dilemma: centralize or embed?
How to build a security team people actually want to engage with
Managing vulnerability backlogs, budget battles, and the patching problem
The real-world incident that moved cybersecurity from priority 43 to priority 1 overnight
How AI is lowering the barrier for attackers including 16-year-olds running perfect phishing campaigns
Why CISO community-building and information sharing matter more than ever
Timestamps:
(00:00) – Introduction
(01:15) – Starting on a North Sea gas platform
(05:30) – Joining Randstad and running the Dutch telco infrastructure
(09:00) – Becoming Randstad’s first global CISO
(14:20) – The “zoom in and zoom out” CISO mindset
(19:45) – What would surprise someone shadowing a CISO for a week
(24:10) – Compliance-heavy vs. risk-driven CISO profiles
(28:30) – Embed vs. centralize: the security team structure debate
(33:00) – How to make security a team people want
(37:15) – Patching, vulnerability backlogs, and the budget war
(42:30) – Building a security narrative that lands with leadership
(46:00) – The incident that changed everything: data breach and crisis response
(53:20) – What makes a great security professional (hint: it’s social skills)
(58:00) – The CISO hiring interview: starting with “What questions do you have for me?”
(01:02:10) – Community building and the 80% overlap problem
(01:07:30) – AI as an attacker accelerant
(01:12:00) – Final message to CISOs: trust each other and share more
Connect with the guest:
Martijn Nykerk: https://www.linkedin.com/in/martijnnykerk/
Follow Cyber Security District:Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/Website: https://www.cybersecuritydistrict.com/All channels & newsletter: https://beacons.ai/cybersecuritydistrict
Apr 14, 2026
58 min

Mar 31, 2026
Mar 31, 2026
1 hr 6 min
In this episode of Cyber Security District, we speak with Chris Zadeh, serial entrepreneur, fintech pioneer, angel investor, and author. Chris was founder and CEO of Ohpen, one of the first cloud-native core banking platforms in Europe, orchestrating more than €100 billion in financial flows. After building and scaling Ohpen for ten years, he exited and shifted his focus to investing, launching a dedicated cybersecurity fund and his own investment vehicle.
From growing up without financial privilege to becoming one of the early digital banking pioneers at Binck in the Netherlands, Chris shares an unfiltered look at execution, obsession, discipline, and what it truly takes to win in regulated markets. Now Chris is investing in cybersecurity startups, Chris explains what he looks for in founders, why AI is reshaping risk and compliance, and why Europe must rethink digital sovereignty.
In this episode, we cover:
Chris’ founder journey: from Binck Bank scale-up years to building Ohpen for 10 years
What “security-first” looks like in fintech, non-negotiables, resilience, and trust with enterprise buyers
Execution culture, exceeding expectations, hiring for discipline, and why culture beats product
The shift to investing and why he started a cyber fund and what he looks for in founders
What’s next in AI-driven risk, compliance + security convergence, and Europe’s digital sovereignty challenge
Timestamps:00:00 – Intro00:14 – Meet Chris Zadeh01:59 – Growing up without financial safety nets03:14 – Joining BinckBank at 2306:52 – Scaling to market dominance08:57 – Wanting to sit at the decision-making table11:36 – Early infrastructure and security lessons14:18 – A firewall shutdown incident17:55 – Leaving to build Open18:48 – The vision for cloud-native core banking22:29 – 744 pages of rejection before first contract27:14 – Migrating €15B live28:09 – Security as non-negotiable32:15 – Hiring discipline and execution mindset35:05 – Culture: exceed expectations or leave37:35 – The cost of extreme execution41:21 – Transitioning to investing44:27 – Why he rejects the “solo entrepreneur” myth49:35 – Launching the cybersecurity fund51:16 – AI, compliance, and new cyber opportunities58:55 – European cloud sovereignty01:04:03 – Signal message to CSOs: stay curious01:06:00 – Outro
Connect with the guest:Chris Zadeh: https://www.linkedin.com/in/chriszadeh/Dark Red (Cyber Fund): https://www.darkred.at/
Follow Cyber Security District:Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/Website: https://www.cybersecuritydistrict.com/All channels & newsletter: https://beacons.ai/cybersecuritydistrict
Mar 31, 2026
1 hr 6 min

Mar 17, 2026
Mar 17, 2026
1 hr 1 min
What if the real cybersecurity crisis isn’t attackers, but our own backlog?
In this episode of Cyber Security District, we sit down with Jaya Baloo, former CISO at major global organizations including KPN, Avast, and Rapid7 and now founder of AISLE™, an AI-native platform designed to not just detect vulnerabilities, but fix them.
After years defending complex enterprises from relentless threats, Jaya made a bold move: stepping out of the CISO seat to build the kind of technology she wished she had. Her mission is clear, eliminate the massive vulnerability backlog that leaves organizations trapped in “security theater” instead of meaningfully reducing risk.
This conversation goes beyond buzzwords. We unpack why detection without remediation is broken, how AI can be applied responsibly to actually close security gaps, and what it takes to build transformative security products in stealth.
In this episode, we explore:
Why Jaya left top-tier CISO roles to start AISLE™
The uncomfortable truth about vulnerability backlogs and unpatched systems
Why identity failures remain a systemic weakness
How AISLE uses AI for detection, remediation, and verification
The importance of stealth mode before going public
What leadership looks like in an AI-driven cybersecurity era
Key Takeaways:
Vulnerability management without remediation is incomplete
Security technical debt is evolving into a societal-level risk
AI must be paired with verification and human oversight
Innovation is essential to preserving true defence in depth
The best CISOs stay curious and challenge their own assumptions
Timestamps:00:00 – Introduction01:20 – Jaya’s transition from enterprise CISO to founder05:45 – The vulnerability backlog problem10:30 – Why identity failures remain systemic16:40 – Building AISLE™: from concept to stealth22:15 – AI for remediation, not just detection29:50 – Verification, testing, and human-in-the-loop controls36:10 – Working with design partners and open-source communities42:35 – The AI shift in cybersecurity48:20 – Leadership lessons from the CISO seat54:10 – Final message to global CISOs
Connect with the guest:Jaya Baloo: https://www.linkedin.com/in/jaya-baloo-558492/
Website: https://aisle.com/
Follow Cyber Security District:Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/Website: https://www.cybersecuritydistrict.com/All channels & newsletter: https://beacons.ai/cybersecuritydistrict
Mar 17, 2026
1 hr 1 min

Dec 10, 2025
Dec 10, 2025
53 min
In this episode of Cyber Security District podcast, we speak with Marco Ramilli, a cybersecurity visionaire, TEDx speaker, and founder of IdentifAI, a deepfake detection company working at the intersection of AI, trust, and digital identity. From writing early sandboxing papers to leading cyber defense teams and selling his previous startup to VirusTotal (Google), Marco has spent the last two decades safeguarding digital borders.
At IdentifAI, he’s now taking on one of the biggest threats of the AI era: manipulated content. Whether it’s fake insurance claims, fraud in football scouting, or synthetic identities onboarding to banks, his platform uses AI to detect AI: verifying whether images, voices, or videos were generated by humans or machines.
In this episode, Marco shares his founder story, why he believes the shift from deterministic to probabilistic computing will reshape cybersecurity, and how his latest startup scaled to enterprise use cases within a year.
In this episode, we cover:
Marco’s hacking origin story and first run-in with his university
Researching malware and voting systems at UC Davis
Founding his first cybersecurity company in Italy when the market wasn’t ready
Bootstrapping a business through 3+ years of break-even before momentum hit
Early ransomware response and reverse-engineering threats
Getting acquired by Tinexta and integrating into VirusTotal
Building IdentifAI to detect deepfakes using AI-powered forensics
From onboarding fraud to football scouting scams, real use cases
The rise of “digital performers” and the ethics of synthetic content
Why deterministic cybersecurity tools are no longer enough
The philosophical shift security teams must make to handle probabilistic models
Advice for scaling startups, hiring A-players, and letting go as a founder
His signal message to CISOs: curiosity will save us
Timestamps:
00:00 – Intro00:14 – Meet Marco Ramilli01:00 – Hacking the campus network (with a for loop!)02:15 – Getting caught, and hired for cyber research03:10 – Reverse engineering malware at UC Davis04:30 – Cybersecurity in Italy: too early, too expensive05:45 – Why compliance was seen as a cost06:20 – Building a company just to be the “owner of his time”07:00 – Early business struggles & staying focused08:30 – Why saying “no” saved his startup10:10 – On embracing failure and learning from loss11:30 – Curiosity, discomfort, and moving to the U.S.13:00 – Sleeping on floors and working without backup14:00 – Founding Yoroi, growing from 4 to hundreds of employees15:30 – The ransomware era and massive inbound traction16:45 – Sandboxing: research, papers, and real-world applications18:00 – Joining Google via acquisition19:30 – Startup phases and letting go as a founder21:00 – Hiring advice: don’t save money on great people23:00 – Launching IdentifAI: how a fake Pope jacket sparked a real mission25:00 – Building AI to detect AI: early model design27:00 – From 80% to 96% accuracy in deepfake detection28:00 – Why images are more dangerous than text29:45 – The weaponization of synthetic media31:20 – How IdentifAI detects voice, image, and video manipulation32:45 – Use cases: banking KYC, insurance fraud, and football scouting35:00 – API-first strategy and enterprise readiness36:30 – “Digital Performers” and the ethics of representation37:30 – Real-time meeting detection via agents39:00 – Why probabilistic AI is changing the rules40:00 – How cybersecurity must evolve to deal with uncertainty43:20 – Deployment flexibility: on-prem or private cloud46:20 – The philosophical challenge of non-deterministic systems49:30 – Final message to CISOs: stay curious
Connect with the guests:
Marco Ramilli: https://www.linkedin.com/in/marcoramilli/
Website: https://identifai.net/
Follow Cybersecurity District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
Dec 10, 2025
53 min

Sep 30, 2025
Sep 30, 2025
55 min
In this episode of Cyber Security District, we sit down with Kim van Lavieren, co-founder and CTO of Dawnguard, a cybersecurity startup that raised millions in funding before registering a company or launching a product. Kim’s story is anything but ordinary, from leading Marines on no-sleep missions to building offensive hacking tools for the Dutch military, to managing massive security teams at Amazon in the U.S., his path combines discipline, vision, and deep technical mastery.
Together with co-founder Madi Abdurazak, Kim is now on a mission to completely rethink how cybersecurity should be done, by starting not with alerts or vulnerabilities, but with architecture, policy, and real business risk. Dawnguard is building a platform that automates secure-by-design architecture using AI, aiming to replace an entire category of cloud security tools before most companies even realize there’s a better way.
In this episode, we cover:
What the Dutch Marine Corps taught Kim about discipline and decision-making
How a military comms officer became a cybersecurity architect
Building secure systems after discovering flaws in weapons room access
Writing offensive tools for the cyber division of the Dutch Armed Forces
Why cyber soldiers may be more impactful than boots on the ground
Kim’s journey to Amazon and running third-party security at massive scale
The mindset shift from “no” to “how” in security engineering
The origin story behind Dawnguard and raising millions pre-product
How Dawnguard is building a new category for architecture-led security
Using AI to design, verify, deploy, and enforce security from day zero
Advice for cybersecurity newcomers, and why the industry must rebrand
How Dutch risk aversion is holding back innovation — and how to break through
Timestamps:
00:00:00 – Intro00:00:47 – Kim's Background: From Marines to Cybersecurity00:03:29 – Training Under Extreme Pressure00:06:28 – Becoming a Communications Officer & Discovering Security Gaps00:08:18 – First Lines of Code at Age 1000:10:19 – When Tech & Physical Endurance Collide00:11:04 – Offensive Cyber Capabilities in the Military00:14:22 – Why Cyber Soldiers Now Matter More Than Physical Ones00:17:05 – Consulting, CISO Roles & Joining Amazon00:18:49 – The Scale & Speed of Security at Amazon00:21:00 – The Origin of Dawnguard00:23:00 – Automating Architecture Compliance with AI00:25:08 – Using Threat Intel & Policy as a Starting Point00:28:02 – Building the Engine: 5 AIs and a Moonshot00:30:46 – Meeting Madi & Finding the Perfect Co-Founder Match00:33:29 – Raising Millions with No Product — and Building a Dream Team00:36:37 – Rise Into Resilience: What the Dawnguard Slogan Really Means00:38:08 – Rebranding Cyber: Why the Industry Needs a Makeover00:39:44 – Advice for People Trying to Break Into Security00:41:03 – Advice for Aspiring Cyber Entrepreneurs00:44:42 – Certifications, Labs & Reality Checks00:47:25 – Going Big Means Accepting Uncertainty00:49:00 – The 5-Year Vision: Replace Entire Security Categories00:50:30 – Final Signal Message to CISOs: Security Is Balance, Not Absolutes
Connect with the guests:
Kim van Lavieren: https://www.linkedin.com/in/kim-v-0645931b4/
Learn more about Dawnguard: https://dawnguard.ai/
Follow Cyber Security District:Laurens Jagt (Host): https://www.linkedin.com/in/laurensjagt/Website: https://www.cybersecuritydistrict.comAll channels & newsletter: https://beacons.ai/cybersecuritydistrict
Sep 30, 2025
55 min



