Podcasts

August 10, 2026

Hacker Valley Media: One Founder Solved the Mobile Security Problem the Industry Refused to See

In this episode of Hacker Valley Media, Hypori founder and CEO Jared Shepard joins host Ron Eddings to explain why mobile device management (MDM) and mobile application management (MAM) can no longer protect enterprise data on personal or compromised devices. Shepard argues that the only durable fix is removing enterprise data from the device entirely, streaming it instead from a secure cloud environment, and applies that idea to BYOD, executive protection, shadow AI, and the Department of War's sixty-day pause on CMMC third-party assessments. Hypori founder and CEO Jared Shepard sits down with Hacker Valley Media's Ron Eddings to break down why MDM and MAM fall short, why BYOD doesn't have to mean more risk, and what changes when enterprise data never touches the device.

COLD OPEN

One of the most important paradigms coming out in the near future is mobile protection. The whole world's moving more and more to a mobile platform. If you have social media on your phone, your device is compromised.

MDM has fundamentally changed, at least in the mobile space. I don't see a lot of people doing that today. Is that the case? They have this new thing called MAM, which is mobile application management. If you're trying to control a device, especially with MAM, you're trying to say you're controlling a container of data on an edge device, and you think that's sufficient. You really think your data is safe?

RON EDDINGS, HOST

What's going on, Hacker Valley fam? Welcome back to the show. It's your host, Ron Eddings. I want you to think about everything that's on your mobile phone right now. Think about your multifactor authentication codes, payments like Apple Pay and Google Pay, and even more pressing and secretive, your messages. Now ask yourself: if you were to lose your phone in the back of an Uber, or even worse, your company's mobile security gets popped, what's your plan?

Our guest today went from homeless high school dropout to Army infantry to founder of a company that's rethinking the edge entirely. This is someone who lost their phone in the back of a cab while traveling overseas, twenty minutes before they were supposed to meet with the Ministry of Defense, and it did not slow them down. Now, how is that possible? All that and more, but first, roll the intro.

Who says tech can't be human? Before we start, here are three things I've been watching from this past month that set the table for today's episode. It's time to hack the headlines.

Number one: the Pentagon hit pause on CMMC. On July thirteenth, the DOD suspended the phase two third-party assessment requirement as part of CMMC. This is the entire thing that government service providers have been nervous and racing toward since November. And now they've brought in a new task force, and they get sixty days to review the whole program.

So why'd they do it? The Department of War CIO, the Honorable Kirsten Davies, looked at how small businesses are about to be facing huge compliance bills, bills that can reach up to six hundred thousand dollars. Imagine this: your company is providing the US government with unique capabilities, and in order to retain your contract, you need to spend six hundred thousand dollars on another business's services. Here's the exact words Kirsten gave: "The math simply doesn't math." And I don't think she's wrong at all. Even the Small Business Administration backed this pause.

So here's what this means for you: if you're anywhere near a defense contract, the audits pause, but the rules are not necessarily too much different. You still have to look at NIST 800-171, and your self-assessments are still mandatory and still enforceable. Self-assessments aren't as good as third-party assessments, I'll say, but they're still really good for the Department of War, and even for companies, because someone has to put their word on the line.

Headline number two: the edge is under active attack. SonicWall put out an advisory on July fourteenth confirming two vulnerabilities in their Secure Mobile Access VPN appliances, and these vulnerabilities were being exploited in the wild. One of them was a perfect 10.0 CVSS score, due to the nature of the vulnerability: unauthenticated remote root access. It's absolutely dreadful and terrible.

Then, on Friday, July eighteenth, researchers at Velexity dropped the story. They said a threat actor they were calling UTA0533 had been chaining these vulnerabilities as a zero-day since June twenty-second, weeks before patches existed. There was no way to work around it. They implanted custom malware inside legitimate SonicWall processes that survived reboots, and hid behind fake error pages, all while secretly and quietly capturing credentials right off the wire.

Why does this keep happening on edge devices? Because that's where all the leverage is. You don't need to hack into a network and do crazy things if you can get into a VPN appliance, because that means all the authenticated sessions going through that appliance let you collect credentials and keys from employees in real time, without any extra work. So what does this mean for you? If you run a SonicWall appliance, you're probably patching and hunting indicators this weekend and into future weekends. Rotating every credential is a good look. But if you zoom out, the thing that brought you security and remote access is the thing that gave the adversary access. It's a pattern. And my guest has a radical answer to this pattern: stop defending the edge, take it off the books entirely.

Finally, number three: a naval defense contractor is bleeding secrets right now. A ransomware crew that calls themselves "the Gentlemen" just listed a major marine systems company as one of their biggest targets, and posted credentials and information on the dark web. They claim they stole over a terabyte of data, and the proof they posted was technical manuals for underwater mine disposal drones.

The company that got hit is ThyssenKrupp Marine Systems, also known as TKMS, which works with the US military. TKMS says the breach was in an environment that was isolated, and that the claims out there are exaggerated. So who are the Gentlemen? A newcomer in the ransomware space, though they actually came from another ransomware gang.

Why does all this matter? It's not the Navy that got hacked. It's not the Pentagon that got hacked. It's the company building technology for the Department of War and the US military. So if you're a contractor, a subcontractor, or a supplier, you are unfortunately the target, because you hold some of the most important crown jewels, but with a fraction of the defense budget. So when you look at all of this: we pause the third-party audit for CMMC, and all of a sudden someone just had their supply chain ravaged.

These three stories have one thread that our guest for today's episode actually built his entire company around, and he's right in the center of it. So without further ado, let's get to the interview.

My special guest and the presenting company is Jared Shepard, founder and CEO of Hypori. Hypori was built by Jared and his incredible team to solve this problem of scale, intelligence, and protection. Jared, I'm so excited to have you on, especially riding on the back of what was just released about the CMMC 2.0 pullback of third-party assessments of your safeguards. But most importantly, Jared, welcome to the show.

JARED SHEPARD, CEO, HYPORI

I hope I can live up to that hype, man. I really appreciate it. I'm excited to get the chance to talk to you.

RON

When we first met, you said something that really stuck out to me, that I hope people, builders, and founders take very personally: you said you had two companies, a services company and a product company you purchased that ultimately became Hypori, and they were going to kill each other if you didn't separate them. I immediately had this vision of two betta fish in a small body of water; they'll go after each other. A lot of companies are so tempted to have a product and build services, or have services and build a product, and you said that's not going to work here. Tell us a little bit about that.

JARED

Yeah, I mean, there are some companies that can pull it off, and the only way you can really do it is you have to have rigid discipline around the separation between those two functions, because they're diametrically opposed. A professional services company survives on low overhead, so it can have the most competitive wrap rate to deliver the best possible service at the lowest cost. A product company is the opposite: it lives on overhead, it builds everything first, then hopes to sell it once it's actually proven the capability works and can scale. Those two things are at odds with each other, and they will ultimately eat each other up if you let them.

I originally thought I could be CEO of both and give myself to both at the same level of commitment, and I was wrong. I almost killed both in the process. So when I really embraced what I knew Hypori could become, and realized how big it could become, I made the decision to spin it out. I took Hypori and hired a CEO to run my professional services company, which is still around and doing great things today.

RON

Amazing. Tell us a little bit about Hypori, because like I mentioned at the beginning, I went through this crazy setup late last year to try to bring virtualization to my desktop, and then realized, oh, I don't have it for my mobile device. If I lose it or get hacked, that's a wrap for me.

JARED

Yeah, so, one, we could have a great conversation about whether I think even desktops will be around in the next ten years or so, because the whole world's moving more and more to a mobile platform. Even Apple has essentially said the Mac OS is going to be largely moved toward a hybrid version of the iOS model. Mobility is going to become the key way everybody interacts with data.

With Hypori, the idea originally was for this really difficult, very bespoke, very unique use case: can you allow a group of government employees to go to a place they're maybe not even supposed to be, buy a cell phone off a host-nation market knowing that phone is probably compromised, think Huawei or similar, on a network that's probably compromised, and still be able to securely communicate in a way that doesn't compromise data or get anybody arrested or dragged into the street? We were able to build a solution that solved that problem.

My epiphany was: if we can do it in this really hard, bespoke, aggressive environment, we could do BYOD. Why wouldn't we be able to empower an employee to access a secure enterprise in a way where the data from that enterprise never leaves? There's no data in transit, no data at rest. It's only ultimately changed pixels. I can interact with that data as if I was in possession of it, but never be in a position to lose the data or compromise it, including if I lose my phone, or if my device is compromised, which, by the way, if you have social media on your phone, your device is compromised. It's just a question of whether it's compromised by a nation-state actor or by a shareholder-owned corporation you chose to accept when you signed off on that user agreement.

RON — SPONSOR MESSAGE

I love working with our sponsors like Hypori because they make you ask yourself the hard questions. So I wanted to ask you, our audience, a question: what if the biggest problem in mobile security isn't about how we protect devices, but the fact that we keep putting sensitive data on them in the first place? That's exactly what my guest Jared Shepard has been challenging for years. After serving in the Army and building multiple technology companies, he founded Hypori around one simple idea: if enterprise data never leaves the enterprise, attackers have nothing to steal. Instead of managing or locking down personal devices, Hypori keeps corporate data inside the enterprise and securely streams the workspace to whatever device you're using. That means stronger security, better privacy for employees, and a completely different way to think about secure mobility. One device, zero worries. Visit hypori.com to learn more.

Now, let's get back to the conversation with Jared about why the assumptions behind mobile security may already be outdated. Thank you, Hypori, for sponsoring this episode.

RON

When I think about the technology you've brought out, the first idea that comes to mind is executive protection, which was a big piece of 2025. A lot of companies were spinning up security specialists who were getting paid exceptionally well to protect executives, so I can imagine that's one of your big use cases. What are some of the other use cases that cybersecurity practitioners and CISOs really care about with the tech you've been working on?

JARED

You hit it on the head. That was actually our first real traction outside of government: a top-five bank saying, hey, we need to give this capability to all our traveling executives, because regardless of what you think your home security posture is, once you travel internationally, especially into Asia, Eastern Europe, or Africa, you're most likely on compromised infrastructure. So the first use case people embraced Hypori for in the commercial world was executive protection: board members, C-level executives.

But then, as it scaled, companies like UBS and Credit Suisse invested in and started using us. We thought they'd say it's because of how secure we are, but they said, that's table stakes, everything has to be secure if we're even going to consider it. What you actually solve for us is a different problem we hadn't even considered: data sovereignty. In Europe, there are data sovereignty laws about how you can move data, privacy rules about who can be in possession of data at any given time. With us, you don't move data anywhere. Data stays in the enterprise. You can enable a traveling employee or executive to interact with data as if they were in possession of it, without ever actually being in possession of it.

RON

Something people used to talk about a lot, and I haven't been part of this world in a while so I'd love a refresher, is MDM. Back in 2010 when I worked at McAfee, they were pushing MDM products so hard, and it required me to give someone else administrator privileges on my own phone, which felt dirty, but in order to check my work email you had to do it. I think MDM has fundamentally changed, at least in the mobile space. I don't see a lot of people doing that today. Is that the case, and how does Hypori differ from that paradigm?

JARED

Yeah, we're night and day. I often say, look, we're not Chevy selling against Ford; I'm not trying to convince you my truck engine or interior is better than yours. We're much more like Tesla selling against Chevy or Ford. Yeah, we have four doors and four wheels, but that's about where the similarities end. We're a different way to approach mobile access to data.

MDM is exactly what the acronym stands for: mobile device management. It's an inventory management platform designed to manage edge devices. If you want to manage your employees' personal phones and be exposed to all the liabilities that incurs, you use MDM. What's happened is MDM evolved into this new thing called MAM, mobile application management. They've gotten a lot of privacy pushback, and people largely don't want MDM on their phone anymore, for the same reasons you didn't. So MDM vendors came up with MAM: instead of managing the whole device, they'll manage an encrypted container on the device and somehow keep that protected container safe from everything else on the device.

That's fundamentally different from the way we look at the problem, which is: nothing should ever be on the device that you don't want potentially exposed to compromise, because the only way to actually protect information is with visibility and control. Even in an encrypted container, if I use MAM, I also have to put endpoint protection on it, meaning I have to put antivirus on it. That antivirus can see every website you go to; it can have a full inventory of your device, otherwise it can't do its job. In a MAM setting, people say, well, it's an encrypted container, that's good enough — except a processor can't use encrypted data. It has to be decrypted to be used. So the first step is it decrypts the data so it can be manipulated. If that edge device is compromised, your data's gone too. Controlling at the edge is fundamentally antiquated, unless you're actually trying to manage corporate-owned devices, in which case, yes, you should have inventory management software protecting that device.

RON

There's this concept of shadow AI, and it's no secret that's going on; it's probably happening in my company and yours. At best, someone might take a screenshot and try to put that into ChatGPT or their favorite AI tool. How does Hypori fit into this new world of shadow AI we're living in?

JARED

For one, we exist largely because of shadow AI; we have to give an alternative to it. But you can't screen-capture our capability. You could, I guess — you and I always get this question — well, what if I take a second phone and take a picture of the first phone? Then you have an insider threat problem; that's not a technology problem.

But shadow IT is a very real problem, and it speaks back to that problem set of habit. If your security mechanism is so prohibitive that people won't use it, it's worthless. People will always go back to what their habits have made them comfortable with. They're going to use Facebook Messenger, WhatsApp, or Signal, even if it's not authorized, not regulated, doesn't meet any requirements. If you don't give them a viable mechanism to safely communicate, one that doesn't compromise their own privacy, safety, and comfort level, they'll find their own. And then corporations, enterprises, and governments end up living with the secondary impact.

RON

My company uses things like Google Drive; we have some network-attached storage as well. Would that live behind Hypori? How would I go about accessing those resources?

JARED

There are some great corporate cloud capabilities out there, whether it's Google, Microsoft, or name the vendor. That's the infrastructure protection side of the house. But if you allow an edge device to actually be in possession of the document, the minute I open a Word doc or an Excel file and start interacting with data on that edge device, you're now exposed to everything on that device, including potential data loss.

Fundamentally, what we're doing is collapsing the attack surface. We're taking your phone, tablet, and maybe even your laptop off the attack surface. As a practitioner, you want to defend your enterprise and use secure enterprise capabilities like Google Drive or Microsoft 365, but you also want to mitigate the risk when you ask an employee to interact with it from an edge device. That's what Hypori is focused on: changing the way the edge is actually looked at.

RON

There's a version of this problem employees cause on purpose, using their personal devices. But with what you're saying, it's like, open it up, let's bring BYOD back. A lot of companies I used to work with had to buy laptops and then figure out how to manage them, and I'm using it at my work office, so that creates a whole other can of worms. You're saying open up those floodgates, but secure the way we're viewing that data by putting it on a different access point.

JARED

Absolutely. Look at my personal phone: I have six other phones on it, essentially, six different environments, including two different Department of Defense networks I can access from my phone. I'm not in possession of any of that data. That data never actually leaves those environments, but I can communicate inside my customer's desired environment, inside their security perimeter, in a way that doesn't introduce additional exposure.

Think bigger picture: this is a cloud-based operating system that operates within a secure enterprise. If I show you Hypori, and launch Outlook, Teams, Slack, everything I do inside of it, it looks like a mobile device or mobile operating system, an iPad or Android, whatever it happens to be. My favorite parlor trick: I say, okay, I'm on four bars of 4G, how much bandwidth do you think I can get? I click speed test. People always guess thirty megs, fifty megs, a hundred megs. It doesn't matter, because it's in the cloud, it runs at the speed of a data center. I pull about four gigabits of bandwidth, because it's running on data center back-end infrastructure, data center processors, data center RAM. That means I can make a faster mobile device than you could ever pack into this form factor.

So what if we could make a faster PC than you could buy from Best Buy, one you could access from your eighty-inch TV on the wall with a wireless keyboard and mouse, for fifteen bucks a month? Now you're talking about actually changing the way the edge works.

RON

I hope anyone watching this would say I'm in, because that's already what we're doing with iCloud on iOS: you're paying ten to twenty-five dollars a month just to maintain a backup of your information. With this, you don't have to put that information on your phone at all. There's no risk of losing the phone and losing the data with it.

JARED

Hypori is really important because we fundamentally challenge the idea of how you secure information. Rather than encrypting data, storing it on an edge device, locking that device down, and compromising people's privacy and convenience in the process, our theory is: don't transmit the data, don't store the data on the edge. Protect your enterprise and allow untrusted devices to interact with information without being in possession of it.

Look at the defense industrial base and the Department of War CIO, who just put a sixty-day suspension on CMMC. People have been bombarding me with notes: oh my gosh, does this mean CMMC is going away? No. What it does mean is DFARS is still in effect, CUI protection requirements are still in effect, NIST 800-171 standards are still in effect. The difference is your company, at least for the time being, for the next sixty days while they evaluate this, doesn't have to have third-party independent verification.

RON

For anyone who hasn't been in the government or DoD space, CUI is confidential unclassified information, right?

JARED

Yep. Confidential unclassified information.

RON

So normally you'd get an external party to say, I looked at your controls, you actually have them in place. But you're saying that's been put on pause.

JARED

Yeah, there were levels of CMMC compliance, and if you were going to work for the Department of Defense, especially if you were going to handle CUI in any way, I think it was Level Two, you had to get an independent auditor to come in and validate you had the appropriate controls in place. Now, from an attestation standpoint, do you have an independent validator come say you've done what you're supposed to do, removing liability? Or do you now take on full liability and say it yourself, and hope you're right?

RON

What does that do to liability? Does that remove liability from the provider, or lessen exposure if there's a lawsuit? What's the value of doing it now, with a sixty-day extension?

JARED

Look, I'm no lawyer, but I'll tell you DFARS and NIST 800-171 are all unchanged. What's been temporarily suspended is the third-party validation that you've done all the work necessary to protect that information in accordance with those regulations. Now it's just you saying that you did. And if somebody files a False Claims Act investigation, and the Department of Justice looks at it and finds you didn't actually do what you claimed, they will find you, to the tune of millions of dollars. I think last year, before any of this came into place, FCA fines had already found over fifty-two million dollars' worth of companies that misrepresented their CMMC status. I don't know if this is a blessing or a curse for defense industrial base customers, but reducing your CUI boundary, where you store CUI and how you transmit it, is maybe more important now than it was twenty-four hours ago, because your exposure may have just gone up.

RON

Underneath all of this, what I'm hearing is why doing the attestation is a good thing for you, and not just you, it's doing the right thing. It's taking some level of oversight and governance and saying, yes, I'm making sure I'm doing the right thing for my country.

JARED

Yeah, look, I'm no C3PAO. I don't make any money on CMMC; that's not my thing. But look at what China's done in the last decade or two. Look at the technology they've come out with, and ask how much of that they actually invented versus stole. Look at their version of the Joint Strike Fighter; it looks just like ours. Was that because they hacked the Department of Defense network? No. They hacked the defense industrial base manufacturer's network and got the plans.

The same thing is happening with AI, with quantum, with everything that helps define America and our allies and ensures we maintain superiority to protect freedom across the world. That comes from the manufacturing of technology. People forget Silicon Valley was created by the Department of Defense; it started in an effort to support the DoD post-nuclear era into the space race. The idea of technical innovation isn't just about using it for wartime, attacking people. It's about protecting what we hold sovereign, protecting our technology edge that employs America and our friendly nations. If those things are simply stripped from us, we find ourselves technology equals, but not manufacturing equals, not freedom equals. The people of China don't enjoy the same freedoms, privileges, rights, and benefits we do. That's part of why their labor is so cheap compared to ours. If an organization like that can use our technology to accomplish their outcomes, the world is not going to be a better place for it.

Look at what Anthropic's Mythos has demonstrated: its ability to change the attack platform, the zero-day exploitation capability of an edge device, from once-a-month Patch Tuesday cycles to patching that has to happen in minutes, maybe hours, because of platforms like Mythos. Anthropic was at least responsible enough to not release it to the world without warning; they did Glasswing, letting a small number of unique companies and government participants see just how exposed they actually are to the legacy systems that are everywhere. China's not going to offer the same restraint. They already claim to have a near-peer capability to Mythos, and if they haven't yet, they will within weeks or months. If you think they're going to hold back from going after everything they can, you're mistaken.

And even when DeepSeek first came out, it was pretty apparent it came through distillation tactics, probably some stealing of confidential information, but also stealing outputs. The outputs are sometimes just as sensitive as the inputs. That's exactly the MDM and MAM problem we talked about earlier: if you're trying to control a device with MAM, you're trying to say you're controlling a container of data on an edge device and that's sufficient, but you have no visibility or ability to control your employee downloading something like DeepSeek. You really think your data's safe? Come on.

RON

Wow, alright, this is amazing. I love these conversations because, one, they're not self-serving, and two, anyone who takes a page out of this book is going to be a little bit better off, and might even get more customers, because having CMMC Level Two with the external audit is impressive. It's like a pen test: you have the records showing someone has actually taken a look and you're taking the problem seriously.

JARED

I think from a contractual standpoint, it'll still become a differentiator, because you'll still have to demonstrate why you've gone above and beyond compared to your peers. But to your point about self-serving: could you argue that what I'm talking about is self-serving for Hypori? Maybe, to some degree. But if you wonder why I'm so passionate about it, it's because my passion is for our country, for where I came from, for what we do. Our nation would be better if we're just better as a nation, and whether that benefits Hypori or not, whether it benefits our nation's veterans or not, it doesn't matter, because if it benefits all of us, it benefits all of us. That's what we have to continuously work at, especially as experts and practitioners in the security space.

RON

It's one hundred percent not self-serving. I appreciate everything you do, but what is self-serving is telling people how they can learn more about Hypori. What's the best way for the audience and our community to learn more?

JARED

Sure, go to hypori.com. We have a whole bunch of great information out there. Click contact us, reach out. I'm an easy guy to find; if you can't tell, I'm passionate, hit me up on LinkedIn. I didn't get here, and none of my team got here, without other people's help and mentoring, so we're always receptive to people reaching out with ideas and thoughts. Let's collaborate to be better together, let's make things better. I'm looking forward to meeting any of you who are interested in learning more.

RON

Love it. Jared, I appreciate everything you're doing. I'm wishing you and the Hypori team nothing but the best. We definitely gotta do it again. And with that, we will see everyone next time.

RON — CLOSING RECAP

Alright, I want to close the loop on one of those three headlines we covered at the top of the show: the pause on CMMC. Starting with the reframe Jared gave us: we blame the auditor, the auditor is constantly giving us a problem, but the auditor is actually our cover. When an independent assessor signs off on something and something goes wrong, you can point to the audit and say they told me it was good. Now that protection layer is gone, and it's just you self-attesting that things are properly set up. And if someone on your own team believes you misrepresented the security posture you presented to the Department of War, that's a False Claims Act investigation, and maybe even millions of dollars in fines.

It reminds me of Jared's seatbelt analogy, and how true it is. People fought against seatbelt regulation for over a decade; a lot of people said, I don't need it, I'm a good driver. But just like with CMMC, if the accident isn't actually your fault, you had every condition right, you were following the lane, but you still end up in a crash, it doesn't matter at that point. You were part of it.

So here's the tension I want you to sit with: the Pentagon has not ruled out canceling third-party assessments altogether. They might not ever come back. So ask yourself: who are my security controls for? Are they for the auditor? For the opportunity to win a contract? If so, you never had a security program, you had a theatrical performance you put on every now and again to make things go your way. We are the practitioners. When the auditors step back, you're still here. You're the standard. So ask yourself this week: would someone on your team disagree with your own self-attestation, and why?

I've got to give a huge shout-out and thank you to Jared and the Hypori team for making this episode happen. And as always, make sure you're subscribed to the Hacker Valley studio wherever you're listening or watching. And with that, we will see everyone next time.