Founders R Us: Tales from recent security CEOs

BSidesSF 2024 · Day 1

Overview

This panel discussion, "Founders R Us: Tales from recent security CEOs," offered a candid and insightful look into the challenging yet rewarding journey of building and scaling cybersecurity companies. Moderated by Leaf from Semrep, the session featured four prominent security CEOs: Umma of Opal Security, Oliver Friedricks of Pangia, Brooke Maata of Rad Security, and Travis McPeak of Resourcly. The discussion delved into critical aspects of startup life, from securing the very first customer and navigating the complexities of fundraising to the personal sacrifices and leadership shifts required to run a successful venture.

Watch on YouTube

Visual summary for Founders R Us: Tales from recent security CEOs
Visual summary for Founders R Us: Tales from recent security CEOs

Key moments

  1. 0:00 Panel introductions: diverse backgrounds and product areas (lease privilege, dev security, behavioral detection, config engine).
  2. 2:00 Discussion on first customer and iterative product development, emphasizing product-market fit validation.
  3. 4:00 Uber as an early Phantom customer, highlighting market opportunity identification for SOAR.
  4. 7:00 Strategies for landing early design partners: demand gen, network, AI-powered outreach, PR, and finding early adopters.
  5. 10:00 Debunking 'if you build it, they will come' fallacy; the grind of sales and Product-Led Growth (PLG) approach.
  6. 12:00 Evolving sales to security people: difficulty reaching CISOs, delegation, and importance of integrations (EKS, GitHub, SIEM).
  7. 19:00 Fundraising insights: Venture-backed vs. bootstrapped, founder market fit, and validating market over building POC for investors.
  8. 27:00 Hardest thing to give up: comfort of engineering work, letting go of control, and the CEO's perspective shift.

Founders R Us: Tales from recent security CEOs

Speakers: Unknown

Conference: BSidesSF 2024

YouTube: https://www.youtube.com/watch?v=BRh8B0bIa9o

Overview

This panel discussion, "Founders R Us: Tales from recent security CEOs," offered a candid and insightful look into the challenging yet rewarding journey of building and scaling cybersecurity companies. Moderated by Leaf from Semrep, the session featured four prominent security CEOs: Umma of Opal Security, Oliver Friedricks of Pangia, Brooke Maata of Rad Security, and Travis McPeak of Resourcly. The discussion delved into critical aspects of startup life, from securing the very first customer and navigating the complexities of fundraising to the personal sacrifices and leadership shifts required to run a successful venture.

The talk is particularly relevant for aspiring entrepreneurs, current startup employees, and anyone interested in the dynamics of the cybersecurity market. It demystifies the often-glamorized startup world, providing practical advice grounded in the speakers' diverse experiences. The panelists shared invaluable lessons on product-market fit, go-to-market strategies, team building, and the unique pressures faced by CEOs in a rapidly evolving industry. Their collective wisdom underscores that while the path to founding a security company is fraught with challenges, it is also an opportunity for profound impact and personal growth.

The conversation highlighted that the cybersecurity landscape is incredibly noisy, with an estimated 5,000 vendors vying for attention. In this environment, differentiation, strategic customer engagement, and a deep understanding of market needs are paramount. The speakers' experiences offer a roadmap for navigating this competitive space, emphasizing the importance of resilience, adaptability, and a relentless drive to solve critical security problems.

Background

▶ Watch: Panel introductions: diverse backgrounds and product areas (lease privilege, ... (0:00)

The cybersecurity industry is characterized by constant evolution, driven by emerging threats, technological advancements, and a persistent talent gap. This dynamic environment creates both significant challenges and immense opportunities for innovation. The panelists, each leading a company addressing a distinct facet of security, provided context from their varied professional backgrounds and entrepreneurial journeys.

Oliver Friedricks, a serial entrepreneur, brought a wealth of experience from multiple successful ventures. His previous companies, Immunet and Security Focus, were acquired by major players like Sourcefire (later Cisco) and Symantec, respectively. His most recent venture, Pangia, also became part of Splunk and subsequently Cisco. This history underscores a pattern of identifying critical security needs and building solutions that attract significant industry attention, often leading to acquisition by larger entities seeking to integrate cutting-edge capabilities. His work with Phantom, an early Security Orchestration, Automation, and Response (SOAR) platform, highlights the continuous drive to automate and streamline security operations.

Umma, founder and CEO of Opal Security, focuses on the ever-critical domain of least privilege and access management. Her insights are rooted in the pain of building similar internal tools at high-growth companies like Discord and Segment, recognizing a universal problem that internal solutions often fail to scale effectively. This experience is a common genesis for security startups: identifying a pervasive internal challenge and productizing a solution for a broader market.

Brooke Maata, CEO and co-founder of Rad Security (formerly Quok), brings a strong sales and go-to-market perspective. Her background includes significant stints at Bugcrowd, Rapid7, and Sonatype, providing her with a deep understanding of how security products are sold and adopted. Her company, Rad Security, tackles behavioral threat detection and response, an area requiring sophisticated analytics to identify subtle anomalies indicative of compromise.

Travis McPeak, formerly a security engineer, founded Resourcly to address the widespread issue of misconfiguration. His company aims to simplify and accelerate the process for developers to produce secure configurations, thereby mitigating a common attack vector. This focus reflects a growing industry trend towards shift-left security, embedding security earlier in the development lifecycle.

The collective experiences of these founders highlight several recurring themes in the security startup ecosystem: the iterative nature of product development driven by customer feedback, the shift from traditional sales models to more nuanced engagement strategies, the intense personal demands of entrepreneurship, and the critical role of market timing and founder-market fit in securing investment and achieving success. The panel aimed to demystify these processes, offering a realistic portrayal of the highs and lows of building a security company in today's competitive landscape.

Key Findings

▶ Watch: Uber as an early Phantom customer, highlighting market opportunity identifica... (4:00)

The panel discussion yielded several critical insights for anyone considering or currently navigating the entrepreneurial path in cybersecurity:

  • The Primacy of the First Customer and Design Partners: Securing the first customer is not merely a sales milestone but a fundamental validation of a product's viability. Travis McPeak emphasized that until a customer engages, a product remains a "science experiment" or a "hobby." The most effective approach to early customer acquisition is through a design partner program, where customers engage early, provide crucial input, and iterate with the startup. This low-friction, high-feedback model helps refine the product and build initial trust. Oliver Friedricks cited Uber as an early Phantom customer, noting their prior experience building similar internal tools (like Facebook's "Blackbird") made them immediately "get it."
  • Evolving Go-to-Market Strategies: The days of effective cold calling are largely over, as the market is saturated with vendors. Brooke Maata highlighted the importance of building "better together stories" and immediate ecosystem integrations (e.g., with EKS, GitHub, Splunk, SIEMs) to allow seamless plug-and-play functionality. Travis McPeak stressed that early-stage companies must leverage every possible channel: investors, angels, friends, and PR from fundraising announcements. Umma added that early adopters are often high-growth tech or product-led companies, not necessarily large enterprises, and that demand generation and account-based marketing (ABM) are crucial, even if sometimes "painful and embarrassing" for engineers. Oliver Friedricks noted the power of product-led growth (PLG), where free access to a product (like Phantom) can lead to inbound interest from even Fortune 50 companies.
  • The Founder's "Death Drive" and Resilience: Starting a company is an all-consuming endeavor that demands extreme dedication and a high pain tolerance. Travis McPeak described it as "not a job," requiring 100% commitment at all times, leading to personal sacrifices like being a "half dad." Umma articulated this as a "death drive"—an inability to let go, channeling insecurity into ambition and survival instinct. This obsession, she argued, is a core trait of successful founders, driving them to pull people and customers along. The panelists agreed that one must be willing to tolerate discomfort and pursue the venture to avoid future regret.
  • Strategic Fundraising Beyond the POC: For Venture Capital (VC)-backed companies, the goal is to achieve a venture scale (a pathway to at least $100 million in revenue), as VCs seek 10x, 100x, or even 1000x returns. Travis McPeak advised against spending excessive time on a "hacky demo" for investors unless technical execution is the primary risk. Instead, founders should prioritize market validation—demonstrating that people care, are willing to buy, and that a budget exists. Founder market fit, or an "unfair advantage" that makes replication difficult, is also crucial. Umma emphasized that market timing is the number one variable correlated with startup success, followed closely by team composition. Oliver Friedricks noted the shift in VC preference from MBAs to product-focused technical founders. The importance of founder alignment with investors and securing warm introductions was also highlighted.
  • The Profound Shift from IC to CEO: Transitioning from an individual contributor (IC) or engineer to a CEO requires a massive expansion of skills and a fundamental shift in perspective. Oliver Friedricks, who spent 30 years writing code, explained that a CEO must learn to hire and manage people across all domains (accounting, legal, sales, etc.) and, crucially, learn to "let go" of control. Umma described this as "altitude switching," where a CEO must constantly zoom between minute details and a broad strategic time horizon, managing their own anxiety while recognizing that employees cannot bear the same level of stress. Travis McPeak deliberately stopped doing engineering work to force himself into the uncomfortable but necessary role of customer engagement, realizing he eventually had "no fucking idea" what his engineers were doing, a testament to the necessary delegation.
  • Learning from Mistakes: The panelists openly shared their biggest mistakes. Travis McPeak regretted waiting too long to fire an underperforming employee, extending a 1.5-month realization into a 4-month ordeal, vowing to maintain a high bar for talent. Umma spoke of the danger of "willing things into existence," pushing deal cycles that should have been disqualified, leading to team burnout and even resignations. Oliver Friedricks pointed to poor market timing, attempting to start a company after the 2008 housing crash with limited funding, and being "way too early for EDR" in 2010, despite building a product akin to CrowdStrike years before its time.
  • Strategic Sales Hiring and Founder-Led Sales: The first salesperson should be a "bad student, good test taker"—creative, problem-solving, and willing to wear multiple hats, rather than a traditional account rep. Brooke Maata mentioned a creative early hire who sent "a wheel of cheese" to customers, demonstrating the need for unconventional approaches. The panelists agreed that founders should lead sales efforts initially (closing deals up to $500k to $1 million in revenue for enterprise products) to understand the deal cycle, gather product feedback, and establish a repeatable sales motion and ideal customer profile (ICP) before hiring a dedicated sales team.
  • Empathy and Integrity in Leadership: While the CEO role is demanding and often requires tough decisions, it doesn't negate empathy. Travis McPeak found his capacity for empathy increased, as he needed to deeply understand people's "ground truth" to gather information. Oliver Friedricks emphasized clear communication and treating people well, even when making difficult choices. Umma distinguished between being "nice" and being "empathetic," stressing that integrity—doing what you say you will—is paramount for building trust. CEOs must hire good people managers to support their teams, recognizing that employees cannot sustain the same level of stress.
  • Self-Awareness for "Firing Yourself": Knowing when to step down as CEO is a crucial act of self-awareness. Umma noted that some founders excel at the "zero to one" stage, while others are suited for scaling to public company status. Oliver Friedricks acknowledged he might not enjoy the "logistic details" of a public company CEO role and would be willing to "tap myself out" if the company's needs surpassed his capacity or interest. Brooke Maata highlighted the political nature of large company leadership and the importance of hiring executives who are domain experts in areas like IPO readiness or marketing, to extend a CEO's longevity.

Technical Deep Dive

▶ Watch: Debunking 'if you build it, they will come' fallacy; the grind of sales and P... (10:00)

While the panel primarily focused on the business aspects of founding security companies, the discussion inherently touched upon the technical underpinnings of their products and the broader technical trends shaping the cybersecurity market. The speakers' companies are all built on solving significant technical challenges within the security domain.

Opal Security's Focus on Least Privilege and Access Management:

Umma's company, Opal Security, operates in the critical and "ever popular" space of least privilege and access management. This area addresses the fundamental security principle of granting users only the minimum necessary access required to perform their job functions. The technical challenge here involves complex identity and access governance, ensuring that permissions are dynamically managed, regularly reviewed, and revoked when no longer needed. Umma's experience building similar internal tools at companies like Discord and Segment highlights a common technical problem: as organizations scale, manual access management becomes untenable, and homegrown solutions often fail to keep pace with complexity and user experience demands. Opal's product likely involves sophisticated backend systems for identity synchronization, policy enforcement, and user-friendly interfaces for requesting and approving access, aiming to provide a scalable and maintainable solution where internal tools often fall short.

Pangia's Shift-Left Security Components:

Oliver Friedricks' company, Pangia, is dedicated to building "components for developers to embed security into their code from the beginning." This directly addresses the shift-left security paradigm, a significant technical trend in modern software development. Instead of retrofitting security controls late in the development lifecycle, Pangia's offerings enable developers to integrate security considerations and checks directly into their development workflows. This could involve Software Composition Analysis (SCA) for open-source dependencies, Static Application Security Testing (SAST) for code vulnerabilities, or Dynamic Application Security Testing (DAST) for runtime issues, all integrated into CI/CD pipelines. The technical goal is to make secure coding practices seamless and automated, reducing the burden on security teams and improving the overall security posture of applications from inception. Oliver's background with Phantom, a SOAR platform, also speaks to the technical drive for automation in security operations, a principle that extends to embedding security into development.

Rad Security's Behavioral Threat Detection and Response:

Brooke Maata's Rad Security (formerly Quok) specializes in behavioral threat detection and response. This technical area moves beyond traditional signature-based detection, which often fails against novel or polymorphic threats. Instead, behavioral detection relies on establishing baselines of normal activity for users, systems, and networks, and then identifying deviations or anomalies that could indicate malicious activity. This typically involves advanced data analytics, machine learning (ML), and potentially artificial intelligence (AI) techniques to process vast amounts of telemetry data, identify patterns, and flag suspicious behaviors. The technical complexity lies in minimizing false positives while effectively detecting sophisticated threats that mimic legitimate user actions.

Resourcly's Configuration Engine for Misconfiguration:

Travis McPeak's Resourcly is a configuration engine designed to solve misconfiguration by making it "really easy and fast for developers to produce good configuration." Misconfiguration is a perennial and often exploited vulnerability across cloud environments, applications, and infrastructure. Resourcly's technical solution likely involves providing developers with guardrails, templates, and automated checks to ensure configurations adhere to security best practices and organizational policies. This could manifest as Infrastructure as Code (IaC) scanning, policy-as-code enforcement, or automated remediation tools that integrate directly into developer workflows. The technical challenge is to abstract away complexity for developers while ensuring robust security outcomes, thereby preventing common configuration errors that lead to security breaches.

Technical Go-to-Market and Product-Led Growth:

The discussion also touched on technical aspects of market engagement. Brooke Maata mentioned adopting "amped," an AI-powered technology that replicates founders' voices to send automated messages for demand generation. This exemplifies how technical innovations are being applied to business development. Oliver Friedricks highlighted Product-Led Growth (PLG), where products like Phantom were offered for free download. This technical distribution strategy allows users to experience the product's value firsthand, effectively serving as a self-service technical proof-of-concept and driving inbound interest.

Founder's Technical Involvement:

While CEOs must delegate, the panelists acknowledged the importance of maintaining a connection to the technical core, especially for technical products. Umma mentioned still running architectural reviews and staying "in the details," even if not writing code. This indicates that for security startups, a CEO's technical acumen remains a valuable asset for guiding product strategy and ensuring technical integrity, even as direct coding responsibilities are relinquished.

In summary, the "technical deep dive" in this context reveals that these security CEOs are building products that tackle complex, real-world technical security problems. Their approaches leverage modern software development principles (shift-left, IaC), advanced analytics (behavioral detection), and robust access controls (least privilege), often driven by their own experiences with the limitations of existing solutions.

Demo / Proof of Concept

▶ Watch: Evolving sales to security people: difficulty reaching CISOs, delegation, and... (12:00)

The conference talk "Founders R Us: Tales from recent security CEOs" was a panel discussion focused on the entrepreneurial journey rather than a product demonstration. Therefore, no live demo or proof of concept of any specific product was presented during the session.

However, the concept of a Proof of Concept (POC) was discussed in the context of fundraising and customer acquisition. Travis McPeak advised aspiring founders against spending excessive time building a "hacky demo" for investors, particularly if the primary risk is not technical execution but rather market validation. He suggested that investors are more interested in evidence of market demand and customer willingness to buy than a rudimentary technical demonstration.

Oliver Friedricks also highlighted an alternative to traditional demos through Product-Led Growth (PLG). He shared an anecdote about Phantom, where customers could download the product for free, effectively allowing them to conduct their own "proof of concept" by experiencing the product's value firsthand. This approach led to significant inbound interest, including from a Fortune 50 customer who discovered Phantom this way. This illustrates that while a formal demo wasn't part of the talk, the strategic use of product access as a form of self-service validation is a key aspect of modern security startup go-to-market strategies.

Defensive Implications

▶ Watch: Hardest thing to give up: comfort of engineering work, letting go of control,... (27:00)

The insights shared by these security CEOs, while primarily focused on the business of building startups, carry significant implications for security defenders. The very existence and focus of their companies highlight critical areas where existing defensive strategies may be lacking or where new approaches are gaining traction.

1. Addressing Foundational Security Gaps:

The products discussed by the panelists directly target pervasive defensive challenges:

  • Least Privilege and Access Management (Opal Security): This underscores the ongoing struggle for organizations to effectively manage access. Defenders should recognize that manual or ad-hoc access controls are unsustainable. The emergence of specialized tools like Opal Security indicates a market need for robust, scalable solutions that automate access governance, enforce least privilege, and provide continuous visibility into permissions. This means defenders should prioritize investing in modern Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions to reduce the attack surface created by excessive or stale permissions.
  • Misconfiguration (Resourcly): Travis McPeak's focus on solving misconfiguration for developers is a direct call to action for defenders. Misconfigurations in cloud environments, applications, and infrastructure are a leading cause of breaches. Defenders must move beyond reactive auditing to proactive prevention. This implies adopting tools and processes that integrate security into the development pipeline, enabling developers to produce secure configurations by default. Solutions like Resourcly's configuration engine can help enforce security policies as code and provide guardrails, shifting the responsibility for secure configuration leftward.
  • Behavioral Threat Detection and Response (Rad Security): Brooke Maata's company addresses the limitations of signature-based detection. Defenders need to evolve their detection capabilities to identify sophisticated threats that bypass traditional defenses. Investing in User and Entity Behavior Analytics (UEBA), Extended Detection and Response (XDR), and other AI/ML-driven security analytics is crucial to detect anomalous behaviors indicative of insider threats, advanced persistent threats (APTs), and zero-day exploits.

2. Embracing Shift-Left Security and Developer Enablement:

Oliver Friedricks' Pangia, which helps developers embed security into code from the beginning, highlights a critical shift in defensive strategy. Defenders can no longer be solely gatekeepers at the end of the development cycle. Instead, they must empower developers to build securely from the outset. This means:

  • Integrating Security Tools into Development Workflows: Adopting SAST, SCA, and DAST tools that are developer-friendly and integrate seamlessly into CI/CD pipelines.
  • Security Training and Education for Developers: Equipping developers with the knowledge and tools to write secure code and manage secure configurations.
  • Collaborative Security Models: Fostering a culture where security is a shared responsibility between security teams and development teams, rather than an adversarial relationship.

3. Strategic Evaluation of Security Vendors:

The panel's discussion on customer acquisition and market validation provides insights for defenders evaluating new security products:

  • Look for Product-Led Growth (PLG): Vendors offering free trials or easy-to-access versions of their products (as Oliver mentioned with Phantom) allow defenders to test the solution's value firsthand without significant commitment, effectively conducting their own POC.
  • Prioritize Integrations: Brooke Maata emphasized the need for startups to build integrations immediately. Defenders should prioritize solutions that seamlessly integrate with their existing security ecosystem (SIEM, SOAR, cloud platforms, identity providers) to avoid creating new silos or operational overhead.
  • Seek Market Validation and Founder-Market Fit: When evaluating new technologies, defenders should look for vendors who demonstrate a deep understanding of the problem they are solving, often stemming from the founders' direct experience (founder-market fit). This indicates a higher likelihood of building effective and relevant solutions.

4. Understanding Market Cycles and Emerging Priorities:

Umma's point about security market cycles (e.g., the current focus on IAM) is vital for defenders. It helps them understand where innovation is concentrated and where new solutions are emerging to address pressing needs. Defenders should stay attuned to these cycles to anticipate future threats and proactively invest in technologies that align with evolving industry priorities.

In essence, the panel's discussion serves as a strategic guide for defenders, highlighting not just the tools and technologies that are gaining traction, but also the underlying philosophies and market dynamics that drive their development. By understanding these trends, defenders can make more informed decisions about their security investments, foster better collaboration with development teams, and ultimately build more resilient defensive postures.

Key Takeaways

  • Customer-Centric Product Development is Paramount: Early and continuous engagement with customers, particularly through design partner programs, is crucial for validating product ideas, iterating on features, and achieving product-market fit. This feedback loop transforms a "hobby" into a viable product.
  • Modern Go-to-Market Strategies are Essential: Traditional cold calling is largely ineffective. Successful customer acquisition in the crowded security market relies on warm introductions, leveraging investor networks, strategic demand generation and account-based marketing (ABM), and immediate ecosystem integrations with platforms like EKS, GitHub, and SIEMs. Product-led growth (PLG), offering free access, can also be a powerful inbound channel.
  • Founding a Company Demands Extreme Resilience and Drive: Entrepreneurship is an all-consuming endeavor requiring a "death drive," high pain tolerance, and significant personal sacrifice. Founders must channel insecurity into ambition, maintain a 100% commitment, and be prepared for constant "altitude switching" between strategic vision and granular details.
  • Fundraising Prioritizes Market Validation and Founder Fit: For venture-backed companies, demonstrating a clear path to $100 million in revenue and proving strong market validation (customer willingness to buy, budget availability) is more critical for early fundraising than a rudimentary technical Proof of Concept. Founder market fit—an "unfair advantage" based on unique experience—and strong alignment with investors are also key.
  • The CEO Role Requires Constant Evolution and Delegation: Transitioning from an individual contributor to CEO necessitates a broad expansion of skills beyond one's core expertise, including hiring, managing, and strategic delegation. It demands high emotional intelligence, clear communication, and the ability to "let go" of direct control, even while maintaining a connection to technical architecture.
  • Market Timing and Learning from Mistakes are Critical: The success of a security startup is heavily influenced by market timing, aligning with current industry cycles (e.g., IAM). Founders must be self-aware, learn from mistakes like delaying difficult personnel decisions or pushing ill-suited deals, and be willing to "fire themselves" if the company's needs evolve beyond their capacity or interest.

About the Speaker(s)

The panel featured a diverse group of experienced security leaders and entrepreneurs, moderated by Leaf.

  • Leaf (Moderator): Works at Semrep, though not in a CEO capacity. He has a background in the security industry, having previously worked at Bugcrowd, where he collaborated with some of the panelists.
  • Umma: The founder and CEO of Opal Security. Her company focuses on the critical areas of least privilege and access management. Umma's insights are informed by her prior experience building similar internal access tools at other high-growth technology companies, such as Discord and Segment.
  • Oliver Friedricks: A seasoned entrepreneur and the founder and CEO of Pangia. Pangia is dedicated to building components that enable developers to embed security directly into their code from the outset. Oliver has a long history in the security startup space, having founded multiple companies that were subsequently acquired by major players. These include Immunet (acquired by Sourcefire, then Cisco), Security Focus (acquired by Symantec), and Pangia itself (acquired by Splunk, then Cisco). He also founded Phantom, an early Security Orchestration, Automation, and Response (SOAR) platform.
  • Brooke Maata: The CEO and co-founder of Rad Security, formerly known as Quok. Rad Security specializes in behavioral threat detection and response. Brooke brings a strong background in sales and go-to-market strategy, having spent 10 years at Rapid7 and also working at Bugcrowd (where she worked with Leaf) and Sonatype.
  • Travis McPeak: A former security engineer who founded Resourcly two years prior to the talk. Resourcly is a configuration engine designed to address the pervasive problem of misconfiguration by making it easier and faster for developers to produce secure configurations.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

This panel discussion offered a glimpse into the realities of founding and scaling security companies, covering topics like early customer acquisition, fundraising, and the personal toll of leadership. While the insights into the business side of security are present, the session lacked any substantive technical depth or novel security research, making it largely irrelevant for an audience seeking advanced technical knowledge.

Heather Calloway (CISO) — STRONG ACCEPT

This panel provided a candid and valuable look into the realities of founding and scaling security companies. The discussion on early customer acquisition, fundraising dynamics, and the personal demands of leadership offers critical context for security leaders navigating the vendor landscape. Understanding the pressures and strategies of these founders is essential for making informed decisions about partnerships and product adoption.

→ Top-rated talks at BSidesSF 2024

All talks from BSidesSF 2024