Defending the Cloud

August 27, 2026

General Catalyst's Mark Crane sits down with Native's Amit Megiddo to talk about the end of dashboards and tickets, and the imperative for AI to fight AI in defending the cloud.

This interview has been edited and condensed. Watch the full video below.

Video thumbnail

Mark: So talk to me about what Native is. What was the gap you saw in the market?

Amit: As an industry, we were getting really good at identifying risk, prioritizing risk, adding context to risk. But we constantly failed to make the jump everyone knew was needed toward active defenses and proactive, preventive controls in cloud security.

From inside AWS I saw the unrealized potential: across AWS, Azure, Google Cloud, Oracle Cloud there's a very rich, robust, trusted security stack that is practically impossible for enterprises to operationalize at scale. The needed leap toward proactive cloud security lies in that native stack so we married the two together. We help enterprises operationalize their CSP-native security stack to build operational, active defenses in the cloud.

Mark: That's the mission. But a mission doesn't get built alone. Talk to me about the team.

Amit: I had the conviction probably two years before I left AWS. What I was missing was the team. So I left and moved back to Israel, because I knew that's where the network would be. One of my first calls when I landed was to a friend, and I told him, "Hey, I'm here. This is happening. " He said, "Well, then you should meet Eyal Faingold," and connected us. Eyal was doing cloud security in the 2010s through Dome9, then led cloud security for Check Point. He and I hit it off immediately. Then Gal, whom I knew from AWS, one of the sharpest technical minds in this space, completed the team. 

Mark: The cloud security Avengers.

Amit: Yes. And honestly, when the three of us came together, the specific idea almost didn't matter. We thought: if there's an opportunity in this space, we'll untap it and execute on it.

Mark: I guess now's the time to say Beetlejuice. If you say it three times, it appears. So: Mythos, Mythos, Mythos. What does this mean for cyber?

Amit: The industry got itself stuck in a place where it can't really do anything: more dashboards, more visibility, more open tickets, then complaints from engineering that we're opening too many tickets. Not really securing. The Mythos moment is a necessity that will force security to mature into actually securing, because there is no alternative. Before, maybe there was a one-in-ten chance that if you didn't get the fundamentals right, something bad would happen. Now it's ten out of ten.

The Mythos moment is a necessity that will force security to mature into actually securing, because there is no alternative.

When you have AI-augmented attackers in the threat landscape, with the speed, the scale, and the leverage they have, this notion of "let's periodically scan the environment, have a dashboard, and open a ticket" doesn't hold water. And from the inside, when your own agents and LLM-generated code are operating in these environments, with potentially destructive, unintentional outcomes—like an agent deleting a production database— you need to architect the environment so AI can be safely adopted within it.

From our very first deployment, we philosophically put in the "implement for me" button. We asked for write permissions. GPT had barely hit when we built it. We knew AI would make this necessary and urgent.

Mark: The way I hear CISOs and CIOs talk about it: historically we papered it over with a whole bunch of sensors, then a whole bunch of people and process. And Mythos is forcing what would have been a 10-to-15-year change into 10 to 15 months.

Amit: Exactly. It's been decades since the last time a human beat a machine in chess. For decades, the grandest chess masters have realized there's no point. And in securing our most critical infrastructure, our data, our way of life, we still think we can put humans against machines.

And in securing our most critical infrastructure, our data, our way of life, we still think we can put humans against machines.

Mark: How do you lead that buyer to water, the one who says, "I can trust you to do parts of it, but not all of it"?

Amit: We're not naive. We don't come to a CISO and say, "Here's a magic button, click it." We put a lot of R&D into simulation and modeling so we can verify that if you click that button, nothing will break. It's transparency: it's audit trails, quick rollbacks, monitoring what a change actually blocks. They try it in one environment, they move slowly, and within a few weeks they just trust it, and it changes their whole operating model.

The bigger shift is that we're moving from software that helps you do the job, which in effect creates more work, to software that just does the job. You click a button and your cloud is now more secure, and stays secure as the environment changes. And we’re feeling it in the market. The CISO of a large, well-known, cloud-native public tech company recently told me, "What I actually need is a platform that will help me manage security proactively, consistently across my different hyperscaler environments, and that's why I'm talking with you." The customer explaining the problem back to you. That's happening.

Mark: You just had such a big smile when you said that. When Native is as successful as you dreamed it would be, what does it look like?

Amit:  Wherever you’re building, whether on the hyperscalers, Snowflake and Databricks, or OpenAI, Anthropic, and GitHub, securing it means Native. There could be a signal from somewhere else in the world about a new attack that just happened, and we immediately architect your entire infrastructure stack to protect you from it.

And as a company: a place that values substance, very no-fluff. You walk past a glass-walled room and they're arguing, someone's scribbling on the whiteboard. Then they get out of the room, go have a drink together, and they're best friends. Something happened in that room that got the company closer to the truth. The ultimate sign of success for us is the number of people who leave and start great companies themselves.

The ultimate sign of success for us is the number of people who leave and start great companies themselves.

Mark: The Native mafia.

Amit: And I'd add: in a world with this speed and scale of AI, security cannot be an observer. It needs to be an active participant: native in the environment, constantly on, constantly adapting, constantly putting up defenses. That's what Native does.

Why did you choose us? You had plenty of choices.

Mark: You had plenty of choices. I very specifically remember it was pouring in New York City, the week after RSA, and I was giving you a term sheet. It was raining sideways, and I was walking, soaking, on 20th Street in Manhattan. And you texted me: "Do you have five minutes?" Which in the investor world is the equivalent of, "Hey, do you have five minutes for me to break up with you?" Coming from a founder: why'd you choose us?

Amit: First of all, it wasn't "us," it was you. GC is an amazing brand, but ultimately I got to know you and Quentin, so I was making a bet on you guys. And I knew that if I go into a room and need to over-explain why this is such a huge challenge and opportunity, that's not the right partner. That clarity, that you saw why and what we were building, gave us the conviction that you were the right partner to build it with.