5 security startup pitches to raise money and eyebrows

Maya Kaczorowski

BSidesSF 2024 · Day 1

Overview

This talk, presented by Maya Kaczorowski at BSidesSF 2024, delves into the challenging yet opportune landscape of security startup innovation. Kaczorowski, an experienced security professional with a background spanning container security at Google, software supply chain security at GitHub, and head of product at Tailscale, shares her "hot takes" on the types of security companies she believes are needed today. The core of her presentation involves pitching five hypothetical security startups, complete with problem statements, proposed solutions, and candid feedback from venture capitalists (VCs) she consulted.

Watch on YouTube

Visual summary for 5 security startup pitches to raise money and eyebrows by Maya Kaczorowski
Visual summary for 5 security startup pitches to raise money and eyebrows by Maya Kaczorowski

Key moments

  1. 5:00 CISO concerns: LLMs, data leakage, workload isolation, Jupyter patching
  2. 7:00 Stagnant market leaders: HashiCorp Vault, Splunk, Okta as targets for disruption
  3. 9:00 New technology enablers: Nix, Deno, WASM, WireGuard, Passkeys, eBPF, LLMs
  4. 12:00 Pitch 1: Trust Verify - AI for vendor security reviews
  5. 21:00 Pitch 3: Fort Alice - Developer-centric secret management
  6. 23:00 Critique of Fort Alice: Hosted solution trust, workload identity vs. secret management
  7. 25:00 Pitch 4: Incident Insight - LLM-powered incident response
  8. 28:00 Pitch 5: Build Stack - Nix-based reproducible builds

5 security startup pitches to raise money and eyebrows

Speakers: Maya Kaczorowski

Conference: BSidesSF 2024

YouTube: https://www.youtube.com/watch?v=ugqc8tARShI

Overview

This talk, presented by Maya Kaczorowski at BSidesSF 2024, delves into the challenging yet opportune landscape of security startup innovation. Kaczorowski, an experienced security professional with a background spanning container security at Google, software supply chain security at GitHub, and head of product at Tailscale, shares her "hot takes" on the types of security companies she believes are needed today. The core of her presentation involves pitching five hypothetical security startups, complete with problem statements, proposed solutions, and candid feedback from venture capitalists (VCs) she consulted.

The talk is not merely a collection of ideas but a practical guide on how to identify viable startup opportunities in the security space. Kaczorowski outlines a methodology for finding good ideas, emphasizing the importance of solving actual problems for actual users who are willing to pay. Her insights are grounded in her career trajectory, where she has consistently identified and pursued "hot trends" in security, coupled with her experience as an angel investor in the security sector.

This article will explore Kaczorowski's framework for ideation, detail each of her five proposed startup concepts, and analyze the technical underpinnings and market feedback for each. It aims to provide a comprehensive understanding of the current gaps and emerging opportunities in security, offering valuable perspectives for both aspiring entrepreneurs and seasoned security professionals looking to understand the future direction of the industry.

Background

▶ Watch: CISO concerns: LLMs, data leakage, workload isolation, Jupyter patching (5:00)

Maya Kaczorowski's approach to identifying promising startup ideas is rooted in a clear, problem-first philosophy. She stresses that a good idea must solve an actual problem for an actual user that they are willing to pay money for. This seemingly simple principle is often overlooked, leading startups to build solutions without a well-defined market need. She advises starting with the underlying issue, not a tool or technology, and being precise about the target user, whether it's a CISO of a Fortune 500 company or a VP at a startup with limited headcount. This precision is particularly crucial in security, where products might be bought by various stakeholders beyond the core security team, such as CIOs, DevOps teams, or even developers.

Kaczorowski highlights several sources for generating good ideas. The first is talking to users and understanding their frustrations. She shares recent complaints from CISOs, noting that approximately 80% of their top concerns currently revolve around AI/ML. These concerns include the use of LLMs within organizations (e.g., "LLM firewall"), preventing sensitive data leakage from external LLM tools, workload isolation for detecting abuse (like training models), validating LLM-generated code, and tagging LLM-generated content. Traditional problems like patching dependencies also persist, with a specific mention of Jupyter notebooks as a new context for this old issue.

Another fertile ground for ideas is replacing existing stagnant market leaders. These are companies or technologies that are ubiquitous but disliked, or have grown so large they are slow to innovate. Examples cited include HashiCorp Vault, Splunk, and Okta, which represent significant market opportunities due to their high revenue, cost, complexity, or lack of modern competitors. For instance, HashiCorp's Vault accounts for a substantial portion of its revenue, indicating a large market ripe for disruption.

Finally, Kaczorowski points to new technology enablement as a catalyst for innovation. Recent advancements can make previously hard or expensive problems feasible. Technologies mentioned include Nix (package manager/OS), Deno (JavaScript runtime), WebAssembly (Wasm), WireGuard (VPN tunnel), Passkeys (password replacements), eBPF (kernel-level programs), and, of course, LLMs (both as a technology to leverage and to secure). She also notes trends like defragging cloud providers (moving to bespoke clouds like Vercel or Superbase) and Product-Led Growth (PLG) as a sales motion that hasn't fully taken off in security. The geopolitical landscape, with increased defense spending, is also identified as a potential driver for new security solutions.

Key Findings

▶ Watch: New technology enablers: Nix, Deno, WASM, WireGuard, Passkeys, eBPF, LLMs (9:00)

The core of Kaczorowski's talk lies in her five hypothetical startup pitches, each addressing a distinct problem in the security landscape, followed by critical feedback from VCs. These pitches serve as concrete examples of her ideation framework in action.

1. Trust Verify: Scalable Vendor Security Reviews

Problem: Fortune 500 companies manage thousands of vendors, each with access to sensitive data, and subprocessors further complicate data visibility. Current vendor risk management (VRM) processes, often involving manual spreadsheets and reviews, are time-consuming, inefficient, and ineffective, as evidenced by the Verizon 2022 DBIR stating 62% of data breaches occur via third-party vendors.

Solution: Trust Verify proposes an AI assistant leveraging LLMs and Retrieval Augmented Generation (RAG). It would be trained on security questionnaires, policies, and public datasets (breach disclosures, subprocessors, privacy policies). Vendors could simply share existing documentation, and Trust Verify would identify missing or inconsistent information, streamlining the review process for buyers.

VC Feedback: VCs viewed this as a "great consulting business" but questioned its market size for venture funding, estimating SecurityScorecard's revenue at $100 million, which is on the smaller side for VC interest. They also debated whether the value proposition was primarily about cost reduction or actual security improvement, and whether spending on such a solution would have a measurable effect on security. Some suggested it might evolve into an "ATM business" (prints money but not venture scale) or that the long-term winners would be insurance companies offering a single vendor score.

2. Secure Bridge: FedRAMP as a Service

Problem: While cloud adoption is widespread, government agencies and their vendors lag due to onerous FedRAMP requirements (e.g., US persons, FIPS-certified cipher suites). The slow pace of FedRAMP authorization (only 335 authorized services since 2013) creates a significant barrier for SaaS vendors to sell to the growing federal cloud market ($20 billion).

Solution: Secure Bridge aims to provide a comprehensive solution for SaaS vendors to quickly gain FedRAMP compliance. This includes automating pre-assessments, generating reports from existing controls, provisioning tenanted environments in cloud providers managed by US persons, and tracking security assessment report gaps with automated reporting linked to existing codebase and infrastructure. The goal is to accelerate FedRAMP authorization to less than a year for FedRAMP Low.

VC Feedback: VCs identified this as a services-oriented business rather than a scalable product, akin to a consultancy with some product support. They noted that it only solves half the problem (compliance), with the other half being the need for a federal go-to-market team. Concerns were raised about the long time to value (months of sales cycle plus months of work), making it a "bad NDR" (Net Dollar Retention) business. While acknowledging the market opportunity, they suggested it might be an "ATM business" or could become a marketplace/channel partner for government, but not a software product.

3. Fort Alice: Developer-Centric Secret Management

Problem: Existing secret management solutions, like HashiCorp Vault, are often too complex and difficult for developers to use, leading to widespread secret leakage (e.g., via trufflehog). Vault's configuration challenges, scaling issues, and recent licensing changes (and IBM acquisition) make it less appealing for a developer-centric workflow.

Solution: Fort Alice proposes a managed hosted secret store designed for developers. It offers built-in encryption, secret rotation, access controls, and auditing. It integrates with existing IDPs for user authentication and uses roles for services like CI/CD pipelines. The key differentiator is a simplified user experience, featuring a command-line interface for secret access and a configuration file for managing access, with secrets loaded in memory based on environment (prod, test, dev).

VC Feedback: VCs acknowledged the clear market and the poor developer experience of Vault. They saw potential for a "bottom-up go-to-market" and good margins due to its tech-heavy nature. However, they questioned if "a little bit better developer experience" was a sufficient differentiator against an entrenched player. A significant concern was the hosted solution model, with sophisticated enterprises being reluctant to trust a random startup with their most critical data, viewing it as "putting all their eggs in one basket." Some VCs suggested the real problem to solve might be workload identity rather than just secret management.

4. Incident Insight: LLM-Powered Incident Response Bot

Problem: Security incident response is a highly manual, time-consuming, and tiresome process, especially for long-lived incidents like Log4j. Incident Commanders struggle to coordinate across teams, track remediations, and maintain communications, diverting focus from critical decision-making.

Solution: Incident Insight is an LLM-powered Slackbot designed to automate and streamline incident response. It summarizes issues using publicly available sources and RAG, provides status updates and summaries, offers critical handover summaries between teams, prompts for next steps, and auto-generates postmortems (including logs, incident summary, and remediation steps). The solution is based on processes established at large tech companies, making them accessible to other organizations.

VC Feedback: VCs noted that this idea sits in a "weird middle ground." The most sophisticated organizations (like big tech) are building homegrown solutions, while the smallest organizations don't need it. The market might be too small. They suggested it could make sense as part of a broader security operations (SecOps) suite (e.g., PagerDuty, FireHydrant). While Google's research showed generative AI could write summaries 51% faster and improve quality, VCs questioned if non-big tech companies would adopt it. However, there was also significant interest, with some VCs having already invested in similar companies, especially given new SEC guidelines on incident reporting.

5. Build Stack: Reproducible Packages with Nix

Problem: Current build systems are widely disliked, lack reproducibility across different people and environments, and struggle with multi-language/multi-environment support. Security is often an afterthought (e.g., SBOM generation), and maintaining build systems requires dedicated teams.

Solution: Build Stack proposes a Nix-based package builder that brings reproducibility to packages, not just the OS. It enables precise point patching during incidents, allowing upgrades of only affected components without retesting everything. Leveraging Nix, it works across all environments, enabling CI/CD as code and bringing modern DevOps practices to the build process.

VC Feedback: The main barrier was that many VCs were unfamiliar with Nix, and those who were expressed concern about recent "spiciness" or drama within the Nix community (likely referring to issues with Determinate Systems). VCs also doubted the ability to make significant money in this space, suggesting it would be hard to convince DevOps teams to switch build systems, especially with security as the primary driver. They felt it didn't offer a "real benefit" beyond running all servers on Nix, and that the difficulty of learning Nix itself was the main hurdle, not the lack of a product.

Technical Deep Dive

▶ Watch: Pitch 3: Fort Alice - Developer-centric secret management (21:00)

Kaczorowski's pitches highlight several cutting-edge and established technologies, demonstrating how they can be leveraged to solve persistent security challenges.

Trust Verify is fundamentally an AI/ML play, specifically utilizing Large Language Models (LLMs) and Retrieval Augmented Generation (RAG). The LLM would be trained on a specialized corpus including security questionnaires, security policies, and public datasets such as breach disclosures, lists of subprocessors, and privacy policies. RAG is crucial here, allowing the model to access and interpret private, vendor-specific documents like risk assessment questionnaires and security policies without needing to be retrained on them. This enables the system to identify missing or inconsistent information by comparing vendor-provided documents against organizational requirements and known security best practices, effectively automating a highly manual review process. The comparison to SecurityScorecard, which relies on "shitty basic web scraping" for superficial checks like expired SSL certificates, underscores the technical leap offered by LLM-driven contextual analysis.

Secure Bridge focuses on automating the complex and process-heavy requirements of FedRAMP compliance. Technically, this involves several components. First, it automates pre-assessments by reviewing existing security controls and integrating with Third Party Assessment Organizations (3PAOs) to generate reports. This likely involves ingesting configuration data, security tool outputs, and policy documents. Second, it provisions tenanted environments within major cloud providers (AWS, Azure, GCP) that are pre-configured to meet FedRAMP technical requirements, including being managed by US persons and using FIPS-certified cipher suites. This abstraction layer allows SaaS vendors to quickly deploy their solutions into a compliant infrastructure. Third, the solution helps track gaps in the Security Assessment Report (SAR) by connecting to the customer's existing codebase and infrastructure, enabling automated reporting on compliance status and remediation progress. This suggests integration with CI/CD pipelines, vulnerability scanners, and configuration management tools.

Fort Alice aims to revolutionize secret management by prioritizing developer experience. The core technical components include a managed hosted secret store that provides built-in encryption, automated secret rotation, robust access controls, and comprehensive auditing capabilities. Authentication would be tightly integrated with existing Identity Providers (IDPs), allowing developers to use their familiar corporate identities. The system would support role-based access control (RBAC) to grant specific services, such as CI/CD pipelines, the ability to load necessary secrets. A key innovation is the in-memory secret management application, which runs locally or alongside build pipelines. This application dynamically loads a specific set of secrets based on the environment (production, test, or development), minimizing exposure. The emphasis on a command-line interface (CLI) for secret access and a simple configuration file for managing access directly addresses the usability issues prevalent in existing solutions like HashiCorp Vault, which is often perceived as overly complex to configure and scale.

Incident Insight leverages LLMs to create an intelligent incident response Slackbot. The bot would use LLMs and RAG to summarize incident details from publicly available sources (e.g., threat intelligence feeds, vulnerability databases) and potentially internal knowledge bases. It would provide real-time status updates and summaries, crucial for long-running incidents. A significant feature is the ability to generate critical handover summaries when incident command shifts between teams or shifts. Furthermore, it would prompt incident responders for next steps based on the incident's context and progress. The most advanced capability is the auto-generation of postmortems, synthesizing information from logs, incident summaries, and remediation steps. Kaczorowski references Google's work, which found generative AI could write incident summaries 51% faster and improve quality, and OpenAI's open-sourced bots for streamlining similar workflows, indicating the technical feasibility and growing interest in this application of AI.

Build Stack proposes a fundamental shift in build system design using Nix. Nix is a powerful package manager and functional programming language that enables reproducible builds. This means that given the same inputs, the build process will always produce the exact same output, regardless of the environment or user. This is achieved by isolating build environments and managing all dependencies explicitly. For security, this is critical for supply chain integrity. The ability to perform point patching during an incident is a direct benefit: instead of rebuilding and retesting an entire application, only the affected component can be updated and deployed, significantly reducing remediation time and risk. By making CI/CD configurable as code and ensuring environmental consistency, Build Stack aims to bring modern DevOps principles to build systems, addressing the widespread dissatisfaction with current, often brittle, build processes.

Demo / Proof of Concept

▶ Watch: Critique of Fort Alice: Hosted solution trust, workload identity vs. secret m... (23:00)

The talk itself served as a conceptual "demo" or "proof of concept" for the startup ideas. Maya Kaczorowski presented five detailed elevator pitches, complete with problem statements, proposed solutions, and market analysis, as if she were pitching to VCs. While no live software or working prototypes were demonstrated, the structured presentation of each idea, including potential challenges and VC feedback, provided a comprehensive overview of the concepts.

Defensive Implications

▶ Watch: Pitch 5: Build Stack - Nix-based reproducible builds (28:00)

The insights from Kaczorowski's proposed startups offer several critical defensive implications for security practitioners:

  • Vendor Risk Management Modernization: The "Trust Verify" pitch highlights the urgent need for more efficient and effective vendor security reviews. Defenders should explore how AI and LLMs, particularly with RAG capabilities, can automate the ingestion and analysis of vendor security documentation. This could move beyond superficial checks to deeper contextual understanding, identifying true risks and inconsistencies, and freeing up security teams from manual spreadsheet reviews.
  • Streamlining Compliance: "Secure Bridge" underscores the immense burden of compliance frameworks like FedRAMP. For organizations operating in regulated environments or selling to government entities, defenders should advocate for solutions that automate compliance evidence gathering, control implementation, and reporting. Leveraging "as-a-service" models for compliant infrastructure can significantly reduce time-to-market and operational overhead, allowing security teams to focus on core security rather than bureaucratic processes.
  • Developer-Centric Security for Secrets: The "Fort Alice" concept emphasizes that security tools must be developer-friendly to be effective. Defenders should prioritize secret management solutions that offer a seamless developer experience, integrating easily with existing IDPs, CI/CD pipelines, and developer workflows (e.g., via CLI). The talk also implicitly warns against the risk of secrets in build pipelines, urging defenders to implement robust workload identity and secret delivery mechanisms that minimize exposure during the build and deployment process.
  • AI-Augmented Incident Response: "Incident Insight" showcases the transformative potential of LLMs in incident response. Defenders should investigate how AI-powered tools can assist Incident Commanders by automating incident summarization, providing real-time status updates, generating handover reports, and even drafting postmortems. This can significantly accelerate response times, improve communication, and allow human experts to focus on critical decision-making and strategic remediation rather than manual administrative tasks.
  • Reproducibility for Supply Chain Security: "Build Stack" highlights the fundamental importance of reproducible builds for software supply chain security. Defenders should push for the adoption of build systems that guarantee consistent outputs across environments. Technologies like Nix offer a path to achieving this, enabling precise point patching during incidents and ensuring that deployed software components are exactly what was intended, thereby reducing the attack surface and improving the integrity of the software supply chain.

Key Takeaways

  • Problem-First Ideation: Successful security startups solve actual problems for actual users willing to pay, requiring deep understanding of user needs and market dynamics.
  • AI/ML Dominance: LLMs and AI are top-of-mind for CISOs, presenting significant opportunities for innovation in areas like vendor risk management and incident response, but also new security challenges.
  • Disrupting Stagnant Markets: Large, entrenched security vendors with complex, expensive, or user-unfriendly products (e.g., HashiCorp Vault, Splunk, Okta) represent prime targets for disruption by more agile, user-centric solutions.
  • Developer Experience is Key: Security tools, especially for developers (e.g., secret management), must prioritize ease of use and seamless integration into existing workflows to ensure adoption and effectiveness.
  • Compliance Automation is a Niche: While compliance (e.g., FedRAMP) is a massive pain point, solutions often lean towards services or consultancy models, making them less attractive for traditional venture capital funding unless they can demonstrate significant product scalability.
  • Reproducibility for Supply Chain: Modern build systems must prioritize reproducibility to enhance software supply chain security, enabling precise patching and ensuring integrity across development and deployment environments.

About the Speaker(s)

Maya Kaczorowski is a seasoned security professional with a distinguished career in identifying and pursuing emerging trends in the cybersecurity landscape. She was previously the Head of Product at Tailscale, where she contributed to the development of modern networking solutions. Her experience also includes significant roles in software supply chain security at GitHub and container security and encryption at rest at Google. Kaczorowski is known for her ability to identify "hot new things" and "breaking edge security problems," having worked on container security in 2017, software supply chain security in 2020, and joining Tailscale in 2021. Beyond her operational roles, she is an active angel investor in the security space, focusing on areas she perceives as lacking and where companies are well-positioned to make an impact. Her investment hypothesis centers on leveraging her time and expertise to foster innovation in the security industry.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk, while not a deep dive into a specific exploit or defensive technique, provides a surprisingly insightful overview of the current security market's pain points and potential solutions. Kaczorowski cuts through the usual vendor fluff to identify areas ripe for disruption, leveraging emerging technologies like LLMs, Nix, and eBPF. Her critique of existing 'stagnant market leaders' like HashiCorp Vault and Splunk is spot on, highlighting where technical usability and real-world effectiveness fall short. It's a valuable perspective for anyone looking to understand where the next wave of actual security innovation might come from, rather than just more 'AI-powered' marketing.

Heather Calloway (CISO) — STRONG ACCEPT

This presentation offers a highly relevant and insightful look into critical gaps within the current cybersecurity product landscape, directly addressing challenges faced by CISOs and security leaders. Kaczorowski articulates real-world problems—from the inefficiencies of vendor risk management to the complexities of secret sprawl and incident response—with a clear understanding of their business impact and operational friction. The proposed startup ideas, while conceptual, are grounded in solving these institutional pain points, demonstrating a keen awareness of where innovation is most needed to enhance governance, improve defender capabilities, and drive organizational resilience. It's…

→ Top-rated talks at BSidesSF 2024

All talks from BSidesSF 2024