Sign in to view Justin’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Justin’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
San Francisco Bay Area
Sign in to view Justin’s full profile
Justin can introduce you to 10+ people at YL Ventures
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
18K followers
500+ connections
Sign in to view Justin’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Justin
Justin can introduce you to 10+ people at YL Ventures
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Justin
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Justin’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Articles by Justin
-
Somaini's Trust Issues
Somaini's Trust Issues
I'm really happy to post that my fun project is a podcast I've been working on, "Somaini's Trust Issues". The show…
75
12 Comments -
Hush Security: Addressing One of the Most Urgent Gaps in Modern InfrastructureSep 10, 2025
Hush Security: Addressing One of the Most Urgent Gaps in Modern Infrastructure
We are proud to announce that Hush Security has emerged from stealth with an $8M seed round to tackle one of the most…
82
4 Comments -
MIND’s Series A Signals the Future of DLPJun 4, 2025
MIND’s Series A Signals the Future of DLP
Few things are more exciting than backing a team that refuses to accept the limits of a stagnant space. MIND just…
48
5 Comments -
Proud to Announce: Miggo Secures Series A Funding to Transform Application SecurityApr 23, 2025
Proud to Announce: Miggo Secures Series A Funding to Transform Application Security
Today, I'm thrilled to announce that YL Ventures portfolio company, Miggo, has secured a $17M Series A funding round…
53
3 Comments -
Getting in Early: How Security Early Adopters Can Change the Security LandscapeApr 30, 2024
Getting in Early: How Security Early Adopters Can Change the Security Landscape
As a security practitioner for over 30 years, my key priority has always been solving my organization’s security…
61
1 Comment -
Welcome, Miggo: Leading Application Detection and ResponseApr 17, 2024
Welcome, Miggo: Leading Application Detection and Response
Application Detection and Response is officially emerging as a distinct cybersecurity category, and I am absolutely…
70
2 Comments -
Joining YL Ventures: From Defining the Needs to Investing in the SolutionsFeb 6, 2024
Joining YL Ventures: From Defining the Needs to Investing in the Solutions
My 30-year career in cybersecurity has run the gamut from being part of the customer and vendor communities to…
84
16 Comments
Activity
18K followers
-
Justin Somaini reposted thisJustin Somaini reposted thisComing out of stealth mode… I'm excited to share that I'm joining Verizon as the incoming CISO. The opportunity to join Verizon at this moment was incredibly compelling. Verizon sits at the heart of critical infrastructure, connecting people, businesses and governments around the world, while undergoing a significant transformation focused on better serving customers and embracing an AI-first future. AI is changing how we build and operate technology, but also the speed and sophistication of the threats we face. I'm excited to continue working at that intersection: enabling responsible AI adoption, strengthening resilience against AI-enabled threats, and protecting infrastructure millions depend on every day. There are natural parallels between Cisco and Verizon. Both operate at enormous scale, are deeply connected to critical infrastructure, and have the opportunity to use their visibility and reach to improve security beyond their own four walls. I'm excited to carry many of the lessons from Cisco forward across an even broader ecosystem. I'm incredibly grateful to Nasrin Rezai for the security program and team she has built, and especially for her support and partnership during the transition. I look forward to building on that foundation and wish her the absolute best in her next chapter. Leaving Cisco was not an easy decision. I'm incredibly proud of what our team accomplished, but what I'll remember most isn't a technology, program or metric. It's the people and culture we built. We created an organization where people challenged conventional thinking, were transparent when things weren't working, broke down barriers, and came together when it mattered most. We navigated some incredibly difficult challenges and still managed to have a lot of fun along the way. Which brings me to the wolf. Among my going-away gag gifts, the team decided they needed something more memorable. So they "borrowed" one of the fake wolves positioned around the Cisco RTP campus to deter geese, wrapped it up, and presented it to me. So, briefly, my Cisco legacy included possession of stolen goose-deterrence technology. For the record, the wolf was returned safely to active duty. 😊 As ridiculous as it sounds, the wolf represents something I'll miss tremendously: a team that could tackle incredibly serious problems without taking ourselves too seriously. That combination of mission, trust, camaraderie and humor is difficult to manufacture. To my Cisco teammates, thank you for your trust, candor, friendship and partnership. You made me a better leader, and I'll always be rooting for you. I also owe a debt of gratitude to Anthony Grieco for his partnership and leadership during my time. It was fun and look forward to the continued partnership! And to my new Verizon teammates, I'm incredibly excited for what's ahead and grateful for the opportunity to join you. Time for the next chapter. #onward
-
Justin Somaini shared thisSo excited to release this week's episode of "Somaini's Trust Issues". I talk with Jason Lish, CISO at Cisco, and Iain Mulholland, CISO at Salesforce. We talk about the impact of AI on Security functions and focus on the impact of increased vulnerability detection and their responses, how to secure production and corporate AI usage, and benefit of AI on Security functions and how it will change the Security Programs in the future. #security, #cybersecurity, #ciso, #informationsecurity, #cso https://lnkd.in/gRNsiXve
-
Justin Somaini shared thisLooking forward to participating in tomorrow's panel on "Building Trustworthy Infrastructure for Agentic AI". Can't wait to discuss solutions to an ever challenging problem. #security, #cybersecurity, #informationsecurity, #ciso, #cso https://lnkd.in/gQMu3KrgBuilding Trustworthy Infrastructure for Agentic AIBuilding Trustworthy Infrastructure for Agentic AI
-
Justin Somaini shared thisThis week on "Somaini's Trust Issues" is my discussion with Austin Cowan, Principal at Heidrick & Struggles. Austin Cowan: https://lnkd.in/gxV88G-8 Support the show and Donate to NCMEC!!: https://lnkd.in/g3pEaqCJ Summary In this conversation, Justin Somaini speaks with Austin Cowan, a principal at Heidrick and Struggles, about the evolving landscape of cybersecurity roles, particularly the CISO position. Austin shares his journey into executive recruiting and discusses the significant changes in expectations for CISOs, emphasizing the need for technical skills and product management capabilities. The conversation also highlights the importance of hiring managers understanding these new requirements and the role of effective communication in the hiring process. In this conversation, Austin Cowan and Justin Somaini delve into the complexities of the CISO role, the challenges in hiring practices, and the importance of succession planning in cybersecurity. They discuss the evolving landscape of cybersecurity leadership, the disconnect between hiring managers and the skills needed for CISO roles, and the necessity for organizations to adapt to the increasing demand for cybersecurity expertise. The conversation emphasizes the need for accountability in the hiring process and the importance of fostering a supportive environment for cybersecurity leaders. #ciso, #cybersecurity, #security, #informationsecurity, #cso https://lnkd.in/g_MAniQN
-
Justin Somaini reposted thisJustin Somaini reposted thisToday I'm excited to announce that Miggo Managed Rulesets are now integrated into AWS WAF, available to every AWS WAF Shield and Shield Advanced customer directly in the console. Here's how it works. We took the Miggo engine behind our WAF Copilot mitigation strategy, the same one that turns validated exploit code into blocking rules, and used it to power a continuously updated ruleset, now native in AWS WAF. Every rule starts from a working exploit, not a CVE description. Each one is tested against bypass and mutation variants in Miggo Lab before it ships. And it keeps updating as attackers move, not on a quarterly cycle. The point of all this is the patch gap: the window between a CVE going public and a patch reaching production. It's been treated as an unavoidable risk for too long. It isn't. Take wp2shell, the WordPress pre-auth RCE chain from earlier this month. Proof-of-concept code was public within days, and exploitation attempts followed. Our customers were already covered, so they got to patch on a safe timeline instead of an emergency one. The rulesets are subscription-free and usage-based, so anyone on AWS WAF can turn them on and see for themselves what closing the patch gap with your existing WAF actually feels like. This partnership has been cooking for a while, and I'm grateful to have worked with the best of the AWS Edge team: Amitai Rottem Eitav Arditti Mark Mac Ewen Justin Kurpius Gopinath Durairaj Amazon Web Services (AWS) Miggo Security
-
Justin Somaini reposted thisJustin Somaini reposted thisOhf ohf! Bloom is officially out of stealth! 🌸 Stay tuned Bloom Security
-
Justin Somaini shared thisWhat a great time to spend with you Aaron Mog! Thanks so much for the time and the insights. Can’t wait to connect again.Justin Somaini shared thisFor 30 years, security never really won. Justin Somaini thinks that's about to change. Justin helped define the modern CISO role — former CISO of Symantec, Yahoo, SAP and Box. He is also an investor, Board member and a former Partner at YL Ventures. In this episode: + The two structural reasons security has always fallen short — and why AI finally changes the math + What he looks for to separate real founders from the hype (and the belief he had to unlearn) + How CISOs actually make buying decisions vs. what they claim in surveys Watch on YouTube: https://lnkd.in/g-CTHx9f Listen on Apple: https://lnkd.in/g5PwKeWa Listen on Spotify: https://lnkd.in/g-K7XMzd
-
Justin Somaini shared thisSo excited to see Bloom Security! Congrats to the team and excited to see this innovation in endpoint security.Justin Somaini shared thisBloom Security is out of stealth! Today is one of the biggest days of my life. The story starts ten years ago. Securing an employee's laptop was nearly a solved problem - a browser, a few apps, some files. You could name what was on the machine. Then the machine changed. AI turned from something you visit into software that acts. Employees assemble their own stacks now, and software installs software - an assistant pulls in an extension, which pulls in a package. The endpoint became an ecosystem that configures itself faster than any review process. EDR was built for malware. This is a different problem. We sat with security leaders and heard the same fear again and again: they no longer knew what was actually running across their fleet, or what it could reach. Not what IT approved, but what's actually running. The day we understood that gap was the day Bloom started. What I'll remember from this stretch is the team. Most of us have built together for years, and still, watching this group leave safe seats and pour themselves into something nobody could see yet was something else entirely. Real enterprises trusted us while we were still a secret. I'm bursting with pride for these people, and today the world finally meets what they built. And what they built is real: live at dozens of enterprises across the US and Europe, backed by a $20M raise led by Glilot Capital, with Ten Eleven Ventures, @Okta Ventures, Runtime Ventures, and angels including the founders of Dig Security (acquired by Palo Alto Networks), Demisto, Snyk, and Talon (by Palo Alto Networks). Full control over what runs on the endpoint - risky installs blocked, dangerous configurations enforced in place - built on complete control into every tool, extension, and package, with risk scored in context. All without slowing anyone down. To our customers: you trusted us early, challenged us hard, and shaped this product more than anything else. And to our investors - you believed and backed us before the market caught up, in a category ripe for disruption. Thank you - it means so much to us. To Ofir Balassiano 🌸 and Itay Frishman 🌸 - it was an instant connection when we started building together more than 5 years ago, and I’m grateful to be building a remarkable company with you. And to our amazing team: you put in the tremendous effort and made Bloom possible and real. It’s time to Bloom! 🌸 Photo credit: Moses Pini Siluk
Experience & Education
-
YL Ventures
******* *******
-
**** ********
*******
-
***** ************
***** ******** *******
-
****** **********
** ********** *********** ******* undefined
-
-
******* **** ****** *******
-
View Justin’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Recommendations received
15 people have recommended Justin
Join now to viewView Justin’s full profile
-
See who you know in common
-
Get introduced
-
Contact Justin directly
Other similar profiles
Explore more posts
-
Horizon3.ai
34K followers
Vulnerability management shouldn’t feel like drinking from a fire hose. 🚒 In a recent N2K | CyberWire episode with Dave Bittner, Horizon3.ai CEO Snehal Antani unpacked one of the most persistent challenges security teams face: too much noise, not enough signal. When every scanner reports tens of thousands of “critical” vulnerabilities, the real work becomes deciding what not to fix — and how to prove which issues actually matter before asking teams to sacrifice weekends and family time. In the episode, Snehal draws on his experience as a CIO, CTO, and leader within U.S. Special Operations to explain why modern defense has to move beyond lists and checkboxes, including: • Why vulnerability scanners show what might be wrong, but pentests show what’s actually exploitable • How attackers chain misconfigurations, credentials, and access paths in ways tools rarely model • What boards really need to understand risk: clear consequences, not heat maps • Why “patching everything” isn’t a strategy — and never was • How continuous, attacker-centric testing builds real cyber resilience The takeaway is simple: defenders think in lists; attackers think in graphs. If you’re not testing from the attacker’s perspective, you’re guessing. 🎧 Listen to the full CyberWire-X episode here: https://lnkd.in/graZwP89. #OffensiveSecurity #pentesting #infosec
29
-
KuppingerCole Analysts
11K followers
🟧 Webinar with Okta on Jan. 22: Creating a Unified View of Identity Risk Enterprises manage various identities with differing risks. Disconnected tools hinder policy enforcement and attack response. An identity security fabric unifies visibility, standardizes controls, and automates responses across all identities and systems. 🎯 Join Arkadiusz Krowczynski and Alejandro Leal to: • Understand why identity is now the primary security control plane—and the primary attack vector • Learn how an identity security fabric unifies tools, workflows, and policies across environments • Discover how to eliminate visibility gaps and identity silos • See how orchestration automates and accelerates threat response • Explore practical steps for securing users, workloads, and AI agents • Learn from KuppingerCole’s research and Okta’s implementation expertise Register: https://okt.to/JBmofH #IdentityRisk #IdentitySecurity #IdentityFabric
7
-
Binalyze
9K followers
When investigations lack forensic clarity, the impact goes beyond response time. It hits breach costs, regulatory reporting, and executive confidence. 📉 $1.1M average cost per breach ⚠️ 68% of CISOs admit inaccuracies in regulatory reporting Our latest CISO report breaks down why this happens and how leading teams are closing the investigation gap with faster, evidence-backed decisions. 👉 Download the report (free) https://bit.ly/4bJ4fLM #CISO #CyberResilience #IncidentResponse #RegulatoryReporting #SecurityLeadership
11
-
Travis Good, MD, CIPM
Workstreet • 6K followers
In my experience, it doesn’t matter what you do with your Trust Center or if you have a SOC 2, you still get a questionnaire. We’ve tested with and without NDA. You still get a questionnaire. We’ve tested with extensive FAQs. You still get a questionnaire. Best case is your customer / prospect tailors the questionnaire to what’s on your trust center. But, you still get a questionnaire.
30
8 Comments -
Box
222K followers
Traditional security architecture reviews don't scale. As systems grow more complex and development accelerates, security teams become bottlenecks. At Box, we're building security architecture for agentic development. Our automated STRIDE threat modeling agent analyzes designs in minutes, producing machine-readable security intelligence that flows directly into coding agents, review agents, and testing tools. The shift: → Late-stage reviews to early design engagement → Static documents to living security input → Bottlenecked expertise to scalable capability AI handles routine analysis at scale. Human architects focus on complex problems requiring judgment and adversarial thinking. Read more: https://lnkd.in/gy8iNGdi
9
-
Sprocket Security
6K followers
Why did the MacArthur Foundation move to a continuous penetration testing model? In this #AoB clip, Seth Arnoff shares two very practical reasons: 🔹 Security visibility year-round Instead of a once-a-year snapshot, continuous testing provides an ongoing view of security health - test, remediate, verify, and repeat. 🔹 Operational efficiency for lean teams With a smaller security staff, managing traditional pentests can be time-consuming. Continuous pentesting reduces back-and-forth, runs largely on its own, and surfaces changes only when attention is needed. The takeaway is simple: better coverage, verified remediation, and less operational overhead. Watch the episode: https://lnkd.in/e2jfU8A8 #OffensiveSecurity #ContinuousPentesting #CyberSecurity #PenTesting #SecurityLeadership #CISO #AheadOfTheBreach #MacArthurFoundation
9
1 Comment -
Denys Kudin
SecurityAttest • 4K followers
NIST SSDF v1.2 (Initial Public Draft, Dec 2025) is a surgical but meaningful evolution of v1.1 (Feb 2022): two new practices shift the framework from “secure SDLC controls” toward “secure SDLC controls + operational resilience + continuous adaptation”. What materially changes: 1. Continuous process improvement becomes first-class (PO.6). SSDF now explicitly requires a closed feedback loop that continuously upgrades dev environments, tools, techniques, and vuln response based on new threats, incidents, and ecosystem changes (e.g., adding/updating artifact scanning for supplier inputs, improving audit/logging granularity for reconstruction, adopting safer languages/features to eliminate entire bug classes). Technically: this turns SSDF into a living control system (think: DevSecOps telemetry - detection/lessons learned - pipeline/toolchain hardening - measurable KPIs/KRIs), not a static checklist. 2. Update robustness and reliability is now explicit (PS.4). SSDF elevates safe delivery of software updates into its own practice: testing in customer-like environments, tiered rollout strategies, rollback mechanisms and resilient update infrastructure while emphasizing minimizing disruption and enabling customer control over updates/configurations. This bridges secure development with release engineering/SRE realities treating updates as a high-risk attack surface and a reliability event stream, not just “patch when vulnerable.” #NIST #SSDF v1.2 implicitly says: “Secure software is not only what you build, it’s how fast and safely you can change it, continuously”.
5
3 Comments -
Anchore
5K followers
The next critical CVE isn't a question of if, but when. Will your team be running a war room with 13 different teams frantically debugging permission issues across dozens of clusters? Or will you run a single query against your SBOM inventory and let your policy engine handle remediation recommendations? Learn how Anchore Enterprise transforms CVE response in our latest article. 🔗 https://lnkd.in/etSgZw2K #SBOM #VulnerabilityManagement #SupplyChainSecurity #DevSecOps
3
-
Insight Assurance
20K followers
If your audit prep still relies on static controls and outdated playbooks, it’s time to adapt. HITRUST’s adaptive assessments (e1 and i1) are grounded in real breach data and threat intelligence—so you’re aligning your controls to what actually happens in the wild. This is what real resilience looks like. #SecurityFrameworks #HITRUST #AuditReadiness #AdaptiveSecurity #RiskMitigation
7
-
OffSeq
818 followers
CISA has released BOD 26-04, a CRITICAL directive requiring federal agencies to prioritize vulnerability remediation using a new risk-based model. Instead of flat timelines, agencies now assign deadlines (as short as 3 days with mandatory forensic triage) based on public exposure, KEV catalog status, exploit automation, and technical impact. This approach targets the most dangerous vulnerabilities first — essential as AI accelerates exploit timelines. While mandatory for federal agencies, CISA encourages private sector adoption to improve resilience and focus on real risk. No patch applies, but organizations should evaluate their asset exposure, leverage CISA's Vulnrichment data, and align remediation policies with BOD 26-04 for better outcomes. Learn more: https://lnkd.in/eAxQEERG #OffSeq #CISA #RiskManagement #VulnerabilityManagement #Cybersecurity
-
Alexandre Dulaunoy
OASIS • 7K followers
After lengthy late-night discussions with Cédric Bonhomme on sightings and KEV formats, we produced a first draft of a generic format for Known Exploited Vulnerabilities (KEV). Initially, we considered extending GCVE BCP-05 using the CVE Record format. However, we ultimately concluded that it may be more appropriate to define a standalone format, allowing sources to publish their KEV data independently. Feel free to comment on the discourse link below. KEV Assertion Format – Draft Specification (potential BCP?) This format describes a generic KEV (Known Exploited Vulnerability) assertion format. The goal is to express who claims exploitation, when, based on what, where it was observed, and with which level of confidence, without turning KEV into full threat intelligence. A KEV assertion is usually very binary and lacking some meta-information. The format adds some information which could better capture details about the exploitation. A majority of the fields are optional except vulnerability, status and evidence.[].source which are recommended. 🔗 https://lnkd.in/eaBUFXie GCVE-EU CIRCL (Computer Incident Response Center Luxembourg) CVE Program
144
11 Comments -
PCA Cyber Security
3K followers
New article on PCA Cyber Security blog: “PCI PTS Compliance: A Necessary Step, But Not the Full Story.” PCI PIN Transaction Security (PTS) compliance ensures payment devices meet baseline tamper-resistance and encryption standards - a must for protecting PINs and transaction data. But as we explain in the article, certification alone doesn’t guarantee security across the full payment solution - backend systems, firmware, communication channels, integrations and real-world attack vectors still matter. 💡 If you’re building or securing payment terminals, ATMs, or other transaction systems, this article breaks down why compliance should be the start, not the finish line. 👉 Read more: https://lnkd.in/dGmDK7vD #PCI #PCICompliance #PaymentSecurity #EmbeddedSecurity #CyberSecurity #PTS #RiskManagement
8
-
Colton Porter
SAINT Technology Services • 2K followers
Your security contractor says compliance is at 98%. Your actual audit results tell a different story. I've observed this pattern repeatedly: organizations rely on vendor self-reporting for security performance metrics, only to discover significant gaps during independent assessments. The challenge isn't dishonesty - it's perspective. Contractors naturally view their performance through the lens of effort and intent. But compliance requires measurable outcomes aligned with your specific risk tolerance and contractual obligations. Independent oversight creates accountability without vendor conflict. It validates that your security investments deliver the protection you're paying for, not just the protection they think you need. When performance visibility becomes vendor-neutral, compliance becomes measurable. GreyShield Group provides intelligence-driven oversight that ensures contractual alignment. Contact us at intelligence@greyshieldgroup.com #VendorOversight #ThirdPartyRisk #SecurityOperations #ContractCompliance
3
-
Acsense
3K followers
Semperis Acquires MightyID: A Milestone for Identity Resilience Semperis’s acquisition of MightyID proves it: identity resilience isn't a 'nice-to-have' anymore. It’s the new standard for protecting your most critical assets from modern threats. 1) Identity systems, particularly Active Directory, are primary attack vectors and single points of failure. Specialized resilience measures are no longer optional. 2) True identity resilience extends beyond traditional backup and recovery to encompass proactive prevention, continuous detection, and rapid, intelligent restoration. 3) This acquisition signals increased investment and innovation in the IAM resilience space, pushing organizations to re-evaluate their current strategies and capabilities. Acsense empowers organizations to build and maintain comprehensive identity resilience. We provide deep visibility and continuous monitoring into your critical IAM infrastructure, ensuring you're always prepared for the unexpected. Dive deeper into what this acquisition means for your IAM strategy and learn why identity resilience is non-negotiable. https://lnkd.in/dgETPnZF #Acsense #IAM #IAMresilience #Cybersecurity #BusinessContinuity
4
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top contentAdd new skills with these courses
-
1h 58m
Building Customer Identity and Access Management (CIAM) in Your Applications on AWS
-
2h 6m
A Bug Bounty Toolkit for Security Researchers
-
13m
A Standalone Project: Build a Program to Encrypt and Decrypt Text Messages Using an Encryption Algorithm to Protect Data from Unauthorized Access