Dell Sells RSA to Private Equity Firm for $2B
darkreading.com
darkreading.com
10MM was also 1/3 of the revenue of that division; that's a big chunk. No reason to think they'd stop that cashflow
I do not trust private equity to main the standards necessary for quality and trustworthy security.
My best guess is that you are confused as to what the term "private equity firm" means. Your post is so entwined with implications that I have no idea what you really mean.
"Private equity" doesn't mean "privately-owned equity". It refers to equity which is not publicly traded.
Likewise, public equity doesn't mean "publicly-owned equity"... it means "publicly-traded equity".
See: https://en.wikipedia.org/wiki/Public_equity
Also see definition 6(b): https://www.merriam-webster.com/dictionary/public
Again, I'm not sure if you live somewhere that this might be different, as you alluded above, but this is generally the case across predominantly English-speaking countries.
I've just started attending a professional English course. :-)
https://www.investopedia.com/articles/markets/111015/10-most...
PetSmart was one success story I heard from this podcast: https://www.wsj.com/podcasts/the-journal/how-petsmart-solved...
Spoiler / Hot Take: if you're overloading the company up with debt (even cheap, short-term stuff) and taking out cash based on "revenue projections" or "realized synergies" it's probably not gonna work out so hot when the loan comes due.
Also, VC returns are distributed according to a power law because most startups won't pan out. Private equity buys companies later in their lifecycle, banking on levering up stable operating cashflow rather than banking on the product becoming the next FAANG unicorn. There's a bit of a continuum between VC -> Growth Equity -> Private Equity.
Their MO is more like (1) take something that is basically working but needs capital (2) work out a deal that gives them a enough leverage (e.g. board input/control, debt financing pressure, etc.) then (3) squeeze it for a quickish exit for the PE and (4) move on to the next.
Doesn't always work, of course, but that's the playbook.
Of course the flip side of that is sometimes, particularly with a young company, they just don't know what the hell they are doing. A PE company could potentially fix some of that, potentially at a reasonable cost.
One way to perhaps think of it is this: VC types are in the business of betting on people, and don't necessarily trust the product. PE types are in the business of betting on products, and don't necessarily trust the people.
As someone who has worked for PE owned companies I can confidently say that unless you consider the thing they’re “supposed to be doing” to be reflecting profit on the books, you’re wrong.
The PE owners of companies I worked for pushed EBITDA over anything else and as a result our product became a leaning Jenga tower of half finished functionality combined with unfulfilled promises to customers. Foundational systems were completely neglected in favor of whatever kept costs low and increased closed ARR focused deals. We sold for many times our previous valuation and not one person I spoke to in the company itself or our customer base felt the product was better, all agreed it was worse.
The expectation is 30% YoY growth with 30% margins. At any cost. No excuses.
Your entire company, all of your software, your assets, your people? You’re a single line in a spreadsheet. You’re a stock certificate. An asset. Raise the value or be fired.
What’s that? You care about your employees? They’re working 14-hour days? You need more people. Go ahead, give all the perks you want. 30 Over 30, baby. I don’t care how you hit the number. Just do it or you’re fired.
Oh wait, you can’t hit these crazy numbers given the staff? Boo hoo. Fired.
Your product is falling apart and you’re plugging holes in a dam to prevent churn? Boo boo. Keep doing it.
We’re out in five years anyway.
We burned a few big clients at a previous gig because the cost-benefit of them wasn't above a certain threshold, even though they were objectively large and consistently growing customers. Few years later one got bought by a defense contractor, the other by a well known consumer goods firm; both expanded their spend. My sales execs were very salty about that...
They didn't get an buyer/exit either -- the big lead declined for reasons they didn't tell us -- and had to reformulate a strategy from scratch, which is when heads started to roll.
Due diligence conducted by whom?
If you've worked at any corporation, you will know that most organizations treat "Security" as a "Cover your ass" org. Security teams exist firstly to prevent the company from going under due to incidents; actual protection of production systems is an afterthought. Consequently, you will have corporations touting all kinds of certifications while their production systems continue to e.g. use md5 hashes for user passwords.
I would ask that you reconsider your views. You would think the buyer in these transactions would conduct due diligence, but consider that the people who are technically competent to do a thorough due diligence are few in number. It is in everyone's interest to let the transaction go through; the security due diligence happens after the decision has been made and rarely can break a deal.
Companies like Duo and Okta ate RSA's lunch; their original core business is now a commodity. RSA's relevance in the industry is greatly diminished.
The RSA tokens are essentially a random number plus form factor. It isn't necessary for the manufacturer to know what the number inside each token is, let alone to store that after the product ships.
But of course it's tempting to do so as a convenience for your customers. Once you set off down this slippery slope you're a dead man walking.
A FIDO token likewise is a random number plus (somewhat more complicated) form factor. If anybody makes RSA's mistake it has the exact same consequences (big hole in your security for whoever knows the number). Hopefully the decisions in FIDO to eliminate conveniences for knowing the magic number, plus RSA's example has been enough that nobody is dumb enough but we shall see.
https://corporate.delltechnologies.com/en-us/newsroom/announ...
1. Spun off businesses that made a profit 2. Paid out dividends that reduced their cost basis
Again, I don't know the specifics of the EMC deal and maybe very well they destroyed value, my point is that this is not as simple as comparing numbers at two points in time.
* Google used to be the obvious "useful search engine" when all others were terrible, but these days they emphasize recency and celebrity to the point where their search engine is almost useless in looking up old articles.
Yes, a lot of bad things happen in the world, but don't forget that a lot of good or just OK happens and never gets reported because it is just normal.
I usually assume PE buyouts will result in a teardown situation, but in this case it was positive for customers and employees. I left for unrelated reasons before the sale completed but friends there say they are happy.
I’ve also worked for firms that got bought by PE and were stripped down to just a few bodies doing bare minimum maintenance and only collecting maintenance fees from existing customers. I’m not sure what this is called, but it seems “coasting” can be very profitable for enterprise software with an install base that has high switchover costs.
Good news for who? The owners? The employees? The customers? The private equity firm?
Answers are yes, no, no, yes.
> Why do they seem to mess things up so badly?
They don't, but they probably aren't optimizing for what you are considering.
For comparison, Imperva, with revenue of ~$300 million annually in 2018 was bought by Thoma Bravo for $2 billion. I have a hard time believing Imperva is worth the same as RSA.