Resilient Cyber
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Resilient Cyber
AI's Cyber Boom
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Jon Sakoda of Decibel joins me to break down AI's impact on cybersecurity startups, venture funding, and why endpoint is the Super Bowl of cyber.
Jon is the Founding Partner at Decibel, an early-stage firm backing technical founders in security and infrastructure. He started his career founding IMlogic, an IM security company acquired by Symantec, then spent over a decade at NEA working with companies like Cloudflare, MongoDB, and HackerOne before launching Decibel. We got into why he thinks AI is only magical if you have a magic power, why Decibel led a $100M seed into Ent, and where the firm is placing its next bets.
In this episode:
- Why Decibel operates like the Navy SEALs next to the big platform funds
- The founder community model and finding the early believers among CISOs
- What separates the founders who finish now that AI lets everyone start
- Ent's $100M seed and the self-driving moment for endpoint security
- Telling genuinely AI-native companies apart from AI washing
- AI eating venture capital and why cyber's best years are ahead
- Open models, frontier labs, and why the cat is out of the bag
- The agentic SOC, Dropzone AI, and driver assistance vs. self-driving
- Startup consolidation cycles and being an N of one
- How buyers and job seekers should evaluate early-stage vendors
- Decibel's next bets, from novel AI models to resilience and cyber insurance
Chapters:
0:00 Intro
0:32 Jon's background and founding Decibel
2:25 Big platform funds vs. specialized firms
3:56 Founders helping founders and early believers
6:22 Scaling beyond the early adopters
7:40 Who finishes the marathon in the AI era
10:19 Founders from outside cyber
12:21 Ent's $100M seed and the endpoint bet
14:53 AI-native vs. AI washing
17:04 AI is eating venture capital
18:55 Open models vs. frontier labs
22:41 The agentic SOC and Dropzone AI
26:03 Consolidation and the startup cycle
29:22 How buyers should evaluate young vendors
31:43 Decibel's next bets and cyber resilience
34:11 Game Day at Black Hat
Connect with Jon:
LinkedIn: https://www.linkedin.com/in/jonsakoda/
Decibel: https://www.decibel.vc
Subscribe for more conversations with security practitioners and leaders, and find my writing at https://www.resilientcyber.io
I think you have a recent piece that argues AI is eating venture capital. If foundation models and AI infrastructure keep absorbing most of the dollars, what does that concentration mean for cyber founders trying to raise in 2022?
SPEAKER_00In cyber specifically, AI has been the greatest gift in a long time. So you are accurate in saying that the vast majority of the new capital that has gone into this business is going to some form of AI infrastructure or foundation model app. Like that part of the industry has consumed a ton of capital.
SPEAKER_01A lot of vendors are claiming agents can replace tier one analysts, things like that. From where you sit across the portfolio, what part of the Gentix stock story do you think is real versus maybe is oversold?
SPEAKER_00I think a lot of people know what it means to have driver assistants in their car, and I think Cod Code is really a great driver assistant in the stock.
SPEAKER_01What is actually separating the founders who finished, knowing that things are everyone can kind of build at this stage and there's a lot of capital and it is a noisy space.
SPEAKER_00AI is really only magical to the extent you have the magic power. Thanks, Chris. Super excited to do this.
SPEAKER_01Yeah, you're someone I've followed on LinkedIn for at least two or three years now at this point. You know, and and you know, I try to broaden my perspective, you know, beyond just cyber practitioners in my in my echo chamber and you know getting more interested in the world of venture and who's funding startups, you know, where the capital's going, all these kind of things. But the for folks that don't follow you already, don't know about you and the team, can you tell us a bit about yourself and the background of the team?
SPEAKER_00One huge fan of the work that you do. I'm also a fan of your work on LinkedIn and I'm a subscriber. So uh very much appreciate what you do. Uh, for those of that I haven't had a chance to meet yet, uh, my name is John John Sakoda. I uh started my first company in cybersecurity in the early 2000s. So you may remember before there was Facebook and Friends, we had instant messaging, AIM, MSN, ICQ. Uh so we didn't have smartphones back then. So all of our social networking was done at work. And uh as you might imagine, that was uh a huge security vulnerability uh between corporate networks and the outside world. So my company was called I am logic. I built an IAM firewall. I stopped bad things from coming in, stopped good things from going out. My company was acquired by Symantec in the mid-2000s. Uh so I'm a founder at heart, love starting early stage tech companies. So my entire career, uh first at a firm called NEA, now at a firm called Decibel, has been committed to helping technical founders at the earliest stage, at pre-product market fit. So when it's super early, uh build technical products for technical buyers. Uh my firm is now seven years old, and uh we've invested in a lot of mutual friends and uh are excited to be a part of this community.
SPEAKER_01Yeah, definitely. You guys uh have some amazing companies in the portfolio, amazing founders and teams. Um it's funny you mentioned ICQ. I can still hear like the messaging sound that you would get, like a whistling type sound if I remember. Yeah, totally.
SPEAKER_00And everyone also remembers their AIM screen name if they were that old.
SPEAKER_01Absolutely, yeah, absolutely. So, you know, I wanted to start there actually with your background, you know, knowing that you've uh built a company, sold it, got acquired, got in the venture, like you know, you you spent over a decade at NEA as I looked you up and kind of dug into your background more uh with companies like Cloudflare, MongoDB, Hacker One before founding Decibel. You know, what convinced you to leave a big platform firm like that and start your own early uh stage fund essentially?
SPEAKER_00Chris, I know you have a military background and a lot of people in cyber have a military background. So the analogy I often use is um you know the bit the big funds are super powerful and they're very scaled. They oftentimes um feel like the larger parts of the armed forces. So for example, I like to say that the big funds are like the Navy. Decibel is trying to be more like the Navy SEALs. Uh so I think sometimes uh we want to do highly specialized work, we want to do that at an elite level. Maybe what we trade off with scale, we get speed. Uh, and I think that that focus allows us, in particular at the early stage, to be quite effective. I think a lot of founders recognize that their advantage early on is speed, and that really comes from specialization. And so we want to be uh we want to be where they are on the field, trying to iterate and innovate as quickly as possible. And uh there are some advantages to being small uh when you're trying to move as fast as possible.
SPEAKER_01Yeah, it makes a lot of sense. And you know, I know you have a uh strong portfolio of technical founders and like a background of believing in found, you know, backing these technical founders, and you've built the, you know, kind of built the firm around founders helping founders. I know you all host like uh rising stars and cyber dinners and so on with like portfolio companies and security leaders. Like what does a community model do uh for a cyber founder that you know maybe a traditional fund that we just talked about, maybe these larger, kind of more structured bureaucratic firms don't do for uh innovative startup founders.
SPEAKER_00Yeah, going back to my analogy of you know, maybe being the Navy SEALs or the more specialized group, our job is to be in the frontier. Uh so together, whether you're a founder or in my case, like somebody that wants to work on the frontier with founders, uh, we need to be out into the field as far as we possibly can. When we're out there, uh not a whole lot of people are also out there. They tend to be like-minded people. People uh who are previously founders or are future founders tend to also uh want to live in the future and see see what is coming next. They often are a little unsettled with the present. I think a part of the reason why founders often start multiple companies is because they just think something can always be better and different. So uh the founder community supports other founders who want to build better, different, more innovative products. Similarly, uh it's lonely out there if you don't have early adopters that believe. So uh we want to surround founders with great early adopters. These are practitioners, our customers, people of all levels of seniority and companies big and small. These are the people that want to try early products as early as possible. You might imagine if I put CISOs in a room, there are some CISOs that are terrified that a company has only deployed its product a hundred times. But there are some CISOs who are super excited to try that first product. Uh and I want to find those people. Those are the early believers and technical founders, and they're the ones that want to have their fingers in the clay and help to shape what comes next. That's really the where the magic is and why we try to build these communities uh so that people feel surrounded by like-minded people.
SPEAKER_01Yeah, I mean, insecurity, whether it's the buyer, the CISO, just everyone in the community, like we're incredibly risk averse by nature, right? And that includes uh acquiring and using new products and changing your tech stack and all those kind of things. I wanted to ask you this, like going a little bit deeper on what you just said there, knowing that you're you know you're in Silicon Valley, the West Coast, like it's very innovative for leaning, everyone's kind of uh wants to be the bleeding edge. Um, how do you f find that that translates, like knowing that you have that community, like where some folks are willing to be early adopters and design partners and things like that, how does that translate when you go to go to scale right now? Maybe everyone's not that Silicon Valley native CISO that's you know cloud native and AI PILD, et cetera. Like, you know, how do you kind of scale that when you go to scale a startup uh you know across the ecosystem, knowing that not everyone in corporate America kind of thinks like that or or builds their security program like that?
SPEAKER_00It's a great question, Chris. And I think we try to train everybody on this. Like we want to try to diffuse our ideas into the market as quickly as we can. And we also want to try and find those early believers as often as we can and as quickly as we can. So the cycle time really to creating product market fit is getting these like-minded people together. Uh, we are constantly trying to raise our hands and broadcast to the world that if you are interested in seeing innovation at its earliest stage, come to our events, subscribe to our podcasts, um, show show up in some format, uh, and we will get to know you. And similarly, we want um our our companies at various different levels of maturity. So some companies are, you know, maybe are have three or four years under their belt, may still seem early for a more traditional company, uh, but three or four years is very different than three or four quarters. Uh and these companies still seem very innovative to the early majority, while at the same time that might seem a little late to somebody who feels like they're always on the bleeding edge. Uh and so we like these are our people, Chris, and they in many ways raise their hands to say, you know, we'd like to meet companies at the early stage, even though that definition is a little different for everybody.
SPEAKER_01Yeah, it definitely uh varies depending on where they are and how mature their organization is and the industry that they work in and so on. And uh, you know, speaking of podcasts, I tell you I consume a good minute of uh of your content you put out there. I caught you on risky business and you had made a comment on there, like uh, you know, I think it was roughly everyone can run the marathon, but it's usually the same few folks who finish first. And it made me wonder now that AI has kind of lowered the barrier of who can build a product or at least build a prototype, um, you know, what is actually separating the founders who finish, you know, knowing that things are everyone can kind of build at this stage, and there's a lot of capital, and it is a noisy space. Like what separates uh everyone from those who actually finish?
SPEAKER_00To fill in some of the context, maybe for those that didn't have the benefit of listening to that risky biz show, I think the point that everyone is trying to assess is given how uh diffuse AI is and how powerful it is, on the one hand, it does make it easier to start a company. So um that's a really joyful thing to say that anyone can become a founder. But at the same time, perhaps the double-edged sword is that means everybody can be a founder. Uh and that analogy of either, you know, starting a marathon, but instead of having 10,000 people having a million, um, is I think maybe one way to think about this power of AI. Like we're all able to do more, and that's fantastic. Everyone can now be a founder, but that means the race is just beginning and you've got a million people starting, and and you know, what is going to really separate people over the course of the journey? What I also said in that podcast, which I would love to repeat here, uh, because I think it is a good way to distill this for anyone trying to be a founder, AI is really only magical to the extent you have a magic power. So I I think when we look at people that are starting companies and using AI and are consistently staying ahead of the pack, it's usually because the AI is really amplifying or accentuating something that is magical or specialized about who they are. So in this particular field, I think there are a lot of really amazing founders that have bespoke knowledge or expertise or methods uh which can be amplified by AI. Those founders are going to do really well. I think to the extent you're a tourist to cybersecurity and you just want to, you know, you see it as a big market and you want to use AI to come into this market, uh, maybe lacking some of the domain expertise and some of the history. I I worry more about those people entering the race because um this is not a straightforward market to attack. And it's got a lot of history, it's got a lot of nuances that are critical. So I think for those of us who've been in the business, AI is really going to help us. For those of us who are just coming in, uh, you got a lot to learn.
SPEAKER_01Yeah, I actually want to uh dig a little deeper on that. I'm not, and I I may totally misspeak here, but if I'm not mistaken, like say looking at Palo Alto networks, like the giant in the industry, uh the CEO there, I don't think he has a cyber background by trade, you know, if I'm not mistaken. And I have you know seen this in my career. Sometimes pulling folks from from other domains, they kind of look at things differently. They bring new ideas because we tend to, again, be very risk-averse and kind of stuck in our way sometimes in security. Have you seen the opposite where someone comes from a different discipline or a different domain, but they bring a fresh set of eyes or a new way of doing something or a new way of looking at problems or perspectives, et cetera, that you know, coupled with maybe a partner or co-founder, right, that has this domain expertise, it can actually be a force multiplier.
SPEAKER_00100%. And maybe just to start with uh Nikesha Aurora, the CEO of Palatin Networks, um, an amazing leader, uh, one of the most talented executives in Silicon Valley, uh, who has helped to create an incredibly valuable company. I think one of the things he's done well is he's acquired domain experts in all of the most important emerging fields. And so if I was to give him a lot of credit, it's uh when he sees an emerging domain, uh, he will usually find an elite-level startup and buy that company well in advance of everybody else, thinking it's an obvious idea. And the team of people that he's assembled inside of Palo Alto Networks augments his natural skills and the superpowers that a large company can have. And so I think that that recipe comes well together. To uh specifically address the startup point, uh, yes, I I do think in in some ways we all have to take a small version of that playbook and figure out where is the domain expertise going to be best expressed, where are um uh you know sort of personal leadership or entrepreneurial talents uh going to come together in a team. And it is uh unquestionably better to have uh multidisciplinary capabilities on your team as opposed to just feeling like you can stay comfortable doing the same thing over and over again.
SPEAKER_01Yeah, well said. I just was curious how you thought about that. And uh again, to your what you said about Nikesh, it's a testament to uh I won't say surrounding yourself with people smarter than you, but you know, people who know things you don't know and have areas of expertise that you don't have and so on. Like it's uh that that's such a critical thing to do in in your career and in your life. You know, I wanted to ask you this that you know Decibel recently led the hundred million seed round, I believe, in Ent, which is founded by a team you know behind RiskIQ and Microsoft Security Copilot with a bet on prevention over detection. You know, if you could walk me through what you saw that justified like a seed round of that size and and why that team actually I've chatted with some of the folks on the team, they're incredibly sharp, but I'm curious from your perspective too.
SPEAKER_00Yeah, I I think uh embedded in this question is does every company need to raise $100 million out of the gates? Or why, for example, in the past have we said five or ten million dollars is the appropriate amount of money, and now maybe you're seeing people raise fifty or a hundred million dollars. Uh to dive into the nuance of Ent specifically, because I think it is a great example of uh the game that is being played on the field. Uh, for those that are not familiar with Ent, it is an amazing team that had previously uh built a startup which was acquired by Microsoft and became um the team behind Microsoft Security Copilot. Ent specifically is trying to reimagine how we do endpoint security using small AI models that are very similar to how computer vision works in autonomous driving. So said a different way, it's the self-driving moment uh for the endpoint. Uh and endpoint is obviously a very big market with incredibly formidable players, people that I respect quite a bit. And I've obviously grown up in this business having been acquired by Semantic in the mid-2000s. So uh I don't take on endpoint without having uh a lot of intentionality. I certainly uh would not expect a customer to take on a startups product if they did not feel like we were in it to win it and we were going to be around for a long time. I certainly think uh the size of the investment is really commensurate with the commitment that we all need to make together to build a company that would be enduring uh to really make a dent in this space. So uh uh it is, I think, uh in many ways uh one of the biggest bets you can make in cybersecurity. Sometimes I call endpoint the Super Bowl of cyber. And that's why I think uh it's appropriate to start out of the gates with the right amount of resourcing and the right amount of commitment, not just from us, but from the entire investor group and also the management team that has come together to try to take on this hill.
SPEAKER_01Yeah, I agree with that. And I think uh to your point, it is like uh the Super Bowl of cyber. It's such a critical uh category. And there's some companies that have uh a long tenure and expertise and and understand the domain very well, so you're gonna have to, again, go big, right, to try to try to compete in that space. Um, you know, I was gonna ask you too. I know you probably see tons and tons of pitch decks, and we know nearly every pitch deck right now is claiming to be AI native. When you're evaluating a company, how do you tell if it's uh gainingly AI native versus a product that's just kind of uh bolting on a co-pilot or kind of uh uh AI painting, I guess you'd say there's different AI washing and so on, like these phrases that we use.
SPEAKER_00I'm so glad you're bringing this up. If I just had one ask for everybody out there that is trying to pitch VCs or even design uh a new startup in today's world, cyber or not, I I don't necessarily think throwing AI into everything or trying to be as AI pilled as as as you reference is really helping everybody. Um you you might imagine that uh one of the things that AI does is it makes a lot of things easy and it also generalizes intelligence. So just to maybe oversimplify, if you have something that that is super special and super unique, um AI tends to uh dull or pivot your idea towards something that's more generalized, and that's because it's a product that is built to generalize intelligence. Uh and so in in the old days, Chris, I think a lot of people would say that the reason why, in particular in cybersecurity, people were successful is we had irreverent people that didn't like to follow rules, uh, built bespoke expertise that no one really understood, and then we were able to codify that expertise and bring it to the world in a way that uh took what might have been viewed as offensive and turned it into something that was powerful and defensive. I still think that's the recipe for today. AI can help you tell that story, but I just hope everyone remembers that like please be irreverent and try to do what you can to uh get outside the the guardrails of what generalized intelligence provides because uh I I definitely think that's like the secret sauce that we all need to invest in.
SPEAKER_01Yeah. So speaking of AI, and I'm sure this is part of what's driving this, like I follow uh folks like uh Peter Walker from Carta, who shares some great visualizations and breakdowns on where the capital's going. And I think you touched on this on the risky biz as well as some of the writing and and and posts you've made. Like you've tracked the VC dry powder for years, uh, and I think you have a recent piece that argues AI is eating venture capital. You know, if foundation models and AI infrastructure keep absorbing most of the dollars, uh what does that concentration mean for cyber founders trying to raise in 2026? Again, like uh even maybe going back to the prior comment about you know trying to AI everything, you know, like uh I'm sure that's driving some of this behavior too.
SPEAKER_00The good news, Chris, is um in cyber specifically, AI has been the greatest gift in a long time. So um I you are accurate in saying that the vast majority of the new capital that has gone into this business is going to some form of AI infrastructure or foundation model lab. Like they they that part of the industry has consumed a ton of capital. But at the same time, uh it's it's clear perhaps to everybody that listens to your show that uh one of the killer apps of AI is hacking. And so um the mythos moment, I think, took what might have seemed like a really niche industry and has put us on the global stage. So the market uh for cybersecurity products almost overnight has gone up dramatically. I don't think that that's well captured in the numbers. And I think the amount of investment that is going into cybersecurity is also going up dramatically, and that's also not captured in the numbers. So I I think my my good news to everybody is um our our best years are now and and and ahead of us, uh, and it is often that these numbers are reported in arrears.
SPEAKER_01Yeah, I uh I've I've definitely written about this a lot where um, you know, the markets uh like uh Kelly Shortridge has a great piece. Markets don't give a you know what about cyber. And uh there's a lot of uh proof that like, you know, uh share prices rebound pretty quickly after incidents and all that. And like we've kind of been wandering through the the wilderness of like trying to get everyone's attention to take security seriously. And I feel like AI is kind of like finally, like finally, people are paying attention and like finally taking these things seriously. So I think it is uh ultimately gonna be a gift in that regard. And as you said, there's a lot of opportunity there both for investors and founders and to address a lot of the you know long-standing security technical debt that's been in this space. I was actually curious, this isn't necessarily a security thing, it could be, but there's been a lot of discussion lately about, you know, we talked about the amount of capital disproportionately going towards models and frontier labs and things like that infrastructure. What do you make of the recent conversation right now around the open source and it catching up to the frontier and the implications uh of that in general, but also for security. Like there's security considerations of using a frontier model versus self-hosting and all the kind of security considerations therein. Like, what do you make of this entire conversation that's kind of going on right now?
SPEAKER_00Aaron Powell Well I'm a huge fan of your work, and obviously I saw what Josh had to say uh yesterday. In in general, just for maybe the readers that haven't had a chance to see all of that, uh probably the biggest part of this debate that I agree with is in in general, there's the cat is already out of the bag. So to the extent that anyone thinks that we can put it back in the bag, I don't think that that's going to be possible. Uh the capabilities of Frontier Labs and open model providers are far enough along that there's really no turning back. So, in my personal view, I think the more that we can diffuse this technology in everyone's hands, the more likelihood we're uh we're going to be able to build the right countermeasures and defenses as an industry to keep up with the advancement. Uh I I think um, you know, sunlight has always been the best disinfectant uh in our industry. I know many of us have been working on that for decades, trying to um take what might have been happening in the dark and bring it into the light. I think when we do that as an internet, we become more resilient. I think when we do that as an industry, uh we build better solutions. So I I personally feel like uh we need to keep these products in the hands of as many people as possible, uh, because there's just no way we're going to be able to restrict it.
SPEAKER_01Yeah, I agree with you completely. And uh it is fine because there's a lot of conversation right now about banning X models, maybe from certain nations or certain types of models, and like that's just not how any of this works. Anyone who's working in enterprise T know IT knows like when you try to ban or block something like users find a way. Uh and you can't, you know, especially with open source, like it's going to be pervasive, it's gonna be forked, it's gonna be duplicated, distributed, like there's no putting the guinea back in the bottle.
SPEAKER_00Well, yeah. And if I could just make one more point, I I think many of us have known for the longest time that there's enough talented people to be able to uh attack. Or hack pretty much anything that we put out into the world. When we think about foundation models, I think a lot of the genius of why hackers can be successful is because now they can just throw their own insights with compute in order to attack surfaces. I think it is super important that all of us wake up to that reality and therefore begin to build countermeasures which are going to require these same products to be working autonomously on our behalf. Many people I know are already working on that. It's been many years of founders collaborating with Foundation Model Labs to get these products into market. I think those are going to be great solutions. And I certainly am optimistic that we'll get this ecosystem balanced the way that it is today.
SPEAKER_01Yeah, I agree with you. I'm excited to see what comes of it. And I think that, again, like there's a lot of opportunity to use AI for good within security, you know, to address all kinds of systemic issues we have over the years within cybersecurity. I wanted to ask you about this category in particular. I know Decibel was early into drop zone AI, which put autonomous agents to work investigating alerts in the SOC. You know, this is a space that's seen so many different startups, so much uh capital. A lot of vendors are claiming agents can replace tier one analysts, things like that. From where you sit across the portfolio, uh, you know, what part of the Gentic SOC story do you think is real versus maybe is oversold? And not particularly to any vendor, but you know, it's just a very that that particular category has gotten so much attention from founders, from capital, you know, that kind of thing.
SPEAKER_00Yeah, maybe just to replay the history, I think the first Chat GPT moment was in the end of 2022. And uh Drop Zone, Edward Woo started uh started the creating the first autonomous SOC product uh in the first quarter of 2023. So um, at least from our standpoint, it's been well over three years of uh building solutions to try to automate uh and augment what people are doing inside the SOC. Uh I I think uh the narrative on this base is that it's been very crowded. I think what is the the truth is a lot of people have been experimenting largely with cloud code to try to figure out how to automate and augment what they do at work every day. I think the unprompted conference is a great example of showcasing all that is possible. So I definitely think the SOC is being automated with AI. And I definitely think people are getting a lot of power out of using AI every day, even if they're just using cloud code credits uh in order to do that. Uh Dropstone has taken the next leap, which is to try to make some of this work self-driving and fully autonomous, uh, because at some point some of the work really should be done without uh a security engineer maybe doing as much of the human in-the-loop work that is currently required with cloud code. In that domain, I think the breakthrough that you saw in foundation models uh starting at the end of last year and going into this year, which has effectively led to the explosive growth of companies like Anthropic and OpenAI, um, they've they've been the huge beneficiary of that. So today I think there's only a small handful of companies that can really do autonomous end-to-end work, and they are one of them.
SPEAKER_01Yeah, it's definitely a a crowded space, but it has like that's because there's so much opportunity, so much potential. We know there's so much tedium, uh cumbersome activities that are manual and ineffective and too much data, not enough human labor, et cetera.
SPEAKER_00Um, and the analogy is well, the analogy, Chris, I often use is um I I I think a lot of people know what it means to have driver assistance in their car. And I think Clot Code is really um a great driver assistant in the SOC. The self-driving car is quite different. And for example, with with Drop Zone, you do need to drive a lot of miles uh in order to be able to go to a customer and to say, given your particular use case, uh we've driven enough miles as an in the industry in order to come to you and say, this is ready for prime time. So after three plus years and now very big advancements in foundation models, uh, I think we are at that self-driving moment in the SOC, which is why I think you're gonna see a lot of change.
SPEAKER_01Yeah, that that's a good point in terms of being early, right? They've gained so much experience and insight into trying to apply this technology to that domain that they can bring the you know, the expertise, that experience to customers. Uh and I have seen some great research uh from DropZone and collaboration with like Cloud Security Alliance and others who give some real-world insight into the adoption and the nuances that you don't often hear you know among the marketing hype. So definitely check that out, check them out. Um I I often write a lot about uh you know the in the cybersecurity market on my resilient cyber outlet, and like you know, there's a flood of AI security startups hitting the vendor landscape. Uh some buyers uh of course feel feel exhausted and overwhelmed. Uh and actually had Ed Ed Sim on the show last week and he said there's I want to misquote him, but he says there's too many damn companies, basically like a lot of these companies aren't gonna make it is kind of what he was saying. Uh from the investor side, how do you think about you know how many of these companies may actually persist and sustain and and thrive uh versus you know some that obviously will not? Like we know uh venture capital is a power law you know ecosystem.
SPEAKER_00Chris, uh just because you and I have grown up in this business, and I I know Ed has too, uh th this ebbs and flows. There's always periods of time when people say there's too many startups and there should be a wave of consolidation. Generally speaking, the consolidation comes. And then there's a uh a moment where people feel like there aren't enough startups and we, you know, we we birth even more. So um uh may I be one of the first, uh, but certainly not the last to say that uh this is a cycle. And we're probably in the part of the cycle where there's been mass proliferation of cybersecurity companies, and that means there's probably going to be a lot more consolidation coming. Uh that certainly shouldn't dissuade people from starting unique companies, though. So I I think sometimes um we forget that starting a company is an N of one business. So if you are a special person with a special idea and now is your moment, uh you you may stare at 3,000 companies that look like they're doing something similar, but if they really aren't doing something similar, you are N of one. Uh so I I don't want the macro picture to dissuade people from getting on the field. Um and I often remind people that you know we're all so small in the beginning relative to the macro picture. So um, you know, if you've got a great idea and you want to start a company and you think now is your moment, um there's no better time than now.
SPEAKER_01Yeah, I agree with that. It's a very, very unique time in industry. Um and it's cyclical. Like it always expands, contracts. It there's never gonna be kind of one one ring to rule them all, you know, as much as a big vendor would love to make the platform push and consolidation. Like it just the category doesn't work like that. There's too many uh specialized areas of expertise and domains, and uh it's just a complicated space. And I don't think it'll ever function like uh with you know, say just Pepsi and Coca-Cola. Like it's it's never gonna be like that. I was gonna ask you this too. We talked about this a little bit in the beginning of uh you know what what founders get from working with a firm like yours uh and talked about security buyers. And there's plenty of CISOs in the audience who buy from early stage startups, you know, uh and I want to expand this to also not just SISOs, but maybe people joining a startup too, like uh on the practitioner side, when they're evaluating a young vendor or a young startup, you know, what should they look at in the company's funding and investor base to judge whether this company will still be around in a couple of years, both from a buyer but also from the talent side of joining a startup?
SPEAKER_00I think every buyer today looks at the dimensions that you that perhaps are obvious. Is it a great team? Do they have a lot of money? Do the investors have some history building these kinds of companies? Maybe that's table stakes. Uh so perhaps uh more nuance to that answer might be how unique is this product? And is this product likely going to have some longevity because I can see this product expanding and doing things uh that others can't do because they're trying to tackle a problem in a unique way, or they have perhaps a unique data set or some unique intellectual property or some unique people that are just not easily replicated. That that that tends to be how I look at the world and maybe how other sophisticated buyers look at the world is I'm gonna partner with this company because I'm I'm gonna get something a little different than if I partner with everybody else. Uh and uh in general, I would say customers would rather partner with an existing vendor if they feel like it's an obvious roadmap addition. But if it's not an obvious roadmap addition and there's unique expertise and you you really need to be best of breed because the the space is changing so quickly, uh then customers would prefer to work with best of breed vendors. And that has been true since the beginning of my career in in this space. And I think it will always be true that the whole point of being the startup is to bring bring some uniqueness uh to the customer environment that they won't get somewhere else.
SPEAKER_01Aaron Powell Yeah, I think there's something to be said about uh being unique rather than just trying to be like everyone else, that that'll make you a more formidable partner, more trusted partner, right, and bring that longevity uh level of assurance, right, to the buyer and to team to practitioners joining your team, you know?
SPEAKER_00At Seed Stage, I always tell founders customers are not buying your product. They're buying a partnership. And so they want to work with you to help shape the environment and protect themselves in a way that um no other vendor is going to do for them, which is why at this stage they're choosing to work with you. And uh to the extent people uh who are starting companies today focus on that uniqueness, it's a lot easier uh sometimes to find customers to lean into you because they understand that they're getting something different.
SPEAKER_01Well said, well said. So last you know, kind of uh official question for you. We talked about ENT and the launch of that. We talked about the rise of AI attacks, kind of compressing the time from attack to compromise and impact, et cetera, from days to seconds. Like you know, looking out over the next two to three years, and I know this is hard to give a singular answer because it's probably in many areas made directions, but like you know, where do you see decibel placing its next bets in security? Are there certain categories or functions or certain areas of security that really have your attention?
SPEAKER_00Aaron Powell I think on the technical side, Ent is a great example of a company that is using novel technology to reimagine how we do uh cybersecurity today. So uh uh I I definitely think that's a field. Uh uh if you think about this being a self-driving or autonomous change, uh there's a lot of underlying pieces that need to be built. Uh and so I tend to coach founders that it it's great to look at these categories, but to look at what is novel uh that we didn't have before. And there are thousands of AI models and lots of new data sources. And uh though those kinds of solutions I think are are really interesting and will continue to be interesting to us. I think from a business perspective, probably the biggest change I hope comes to this industry, Chris, is instead of this feeling only like a threat detection and response business where we're you know constantly looking at data and and firing off alerts, um, I think one of the great opportunities is to bring business context into cybersecurity and to um think about what we do as creating resiliency inside of a company so that um, you know, ransomware really isn't just paying a fine, but it's actually keeping the bank and the lights on and you know that there's a lot of economics at stake. And in the future, I think uh there's so much at stake that people will spend a lot more money on cybersecurity because um there's really economic despair that comes from not keeping your infrastructure uh humming all day long. So um I think cyber insurance could be a much bigger business. I certainly think resiliency in and of itself is a much bigger business than just that detection of response alone.
SPEAKER_01Yeah, I I love it. And you know, of course, being on the Resilient Cyber Show, you won't hear me argue against uh that case. I agree with you completely. Uh I lied about the last question. I know you all have some events coming up at Black Hat, like a game day event, you know, a happy hour and so on. Uh tell folks about that before we jump off.
SPEAKER_00Yeah, I'm super excited that we're partnering with you on this event. So um on uh Tuesday at Black Hat, uh, we are known for a founders helping founders event, uh, which we've now expanded to be an entire day. Uh, and that day is called Game Day. It's really modeled as uh after the college game days that you see on TV. We're gonna have uh a giant stage, we'll be bringing lots of founders, we'll be bringing lots of early adopters, and uh we hope if you're in town you'll come and uh maybe uh if we have a chance at the end, we'll share a registration link.
SPEAKER_01Awesome. Yeah, definitely we'll do that with folks who are tuning in. And uh I appreciate you jumping on. I'm looking forward to hanging out in person soon. And again, if you're not following John, please do. He drops some great insights about the intersection of venture capital with software, technology, and of course cybersecurity. So, John, thanks so much for joining me. Thanks so much, Chris. I had a lot of fun. Awesome. Take care.