Does anyone have the same feeling? Why it would be this way?
Does anyone have the same feeling? Why it would be this way?
Most business don't have budget allocated at all for security. Big corps are the exception, but then you'll have the trust issue: they are unlikely to do business with startups when it comes to security.
I have also found that it's hard to find security experts who are willing to work for a startup. Given the salary options that security techs can get at big-corp/government/military, it's hard to be able to compete.
Consulting seldom requires venture capital and cannot scale at the level VCs expect.
Blinky boxes can, but customers are slowly catching on to the fact that adding another blinky box to the network is really not improving their resilience all that much.
On top of that, it's not always easy to identify the real economic buyer in an organisation, and e.g. a CISO might not have the authority to decide on installing new appliances but needs to collaborate with e.g. IT. It all makes for convoluted and longer sales cycles.
Personally I don't think any serious pentester will spend considerable time in this model though.
That said, I also think that one of the main challenges for buyers of pentest services these days is to evaluate the quality of a report or of the work done. Thoughts on how to improve that are most welcome.
I think the trick would be - somehow allow the blinky box to be secure (how do you even do updates if the networks you are "protecting" are not on the internet), this is difficult. And then giving the boxes away for free with a limited amount of stuff they can do without pen tester involvement.
Still is massively problematic.
From participating in that, my experience was that it’s really hard to disrupt in cybersecurity because businesses are skeptical about using young companies with no reputation and a beta product.
So it’s hard to start showing revenue or traction to get funded. The hunt for revenue then also forces you to focus on things like phishing protection instead of discovering zero days.
As to why there aren't many others, that's a great question. It's a hard space to get started in, since security is mission critical for essentially everyone, so that likely doesn't help matters. There's a lot more that needs to go into a viable MVP in cybersecurity than in other areas as well, since there's much less room for error and jank.
Those reasons likely contribute, but none of them are hard blockers.
From my experience working with a number of companies, the challenge seems to just come down to a lack of people in the industry.