Wiz's $32B GTM Playbook
cybersecuritypulse.net
cybersecuritypulse.net
The main elements of the aesthetic that I can pinpoint are things like everything being a superlative ("security leaders" instead of just "people who work in security", "legendary investors" instead of just "experienced/well-known investors"), the bullet format, heavy use of buzzwords when more everyday words would do, etc.
It comes off as trying to elicit a fake "let's all get hyped up and build unicorn moonshots wooo" feeling.
for this specific company, there is specific value to Google, that is included in the valuation. this isn't unfair at all; lots of startups are acquired for strategic value, not intrinsic value.
It may have been lightly edited & enriched by a human, but most of this article was written by an AI.
>Strong, proven founding team (Adallom founders + Microsoft Cloud Security Leadership) Great, sticky product Solving deeply felt pain point(s) Timing (founded just as the world goes remote due to COVID-19 + cloud boom) Legendary investors + network effects (Sequoia Capital, Cyberstarts, Index Ventures etc.) Lots of early funding ($480M+ within a year of emerging from stealth ) Relentless execution
Why is nearly half a billion in funding so far down on the list?
That’s probably the most important factor here
Capital alone won't make a business succeed, and more capital won't make a business necessarily better. A big investment is typically the result of doing everything right before that. They would have never been able to get that amount of capital without a very solid foundation.
Capital is just a small piece of a business, it's not the hardest part by far. Capital is also relatively accessible, it's not an 'unfair' thing. There seems much unfairness sentiment nowadays where people think companies with access to lots of capital are guaranteed to succeed, like some kid with rich parents. Many seem to think that all there is between them and success is money, but in reality that's rarely the case.
Hilariously out of touch, even for a hackernews comment.
Yes, Rich kids tend to have better chances than poor kids. Get in any trouble, you'll have a decent lawyer. You'll attend better schools, your parents will probably buy or help you buy your first home.
Need a doctor or want to see a therapist, you can do so within 24 hours. I'd even argue therapy is largely a luxury for the middle class and up- most of the time Medicare doesn't cover it at all or you have like a year waiting list.
I've been evicted twice in my youth and now I've made 6 figures for a good while.
Money makes things easier. You might run into issues with your friends trying to rob you, but they'll rob you when you're poor too.
Likewise, a company with no funding is basically an idea. Might be a good idea, might be a God awful one.
Having launched a couple of dead startups that started with several months of writing code first, this way definitely sounds better.
This is basically what startup 101 tells you. This is what every successful entrepreneur will tell you. This is what every coach tells you. This is what every entrepreneurial book or blog will tell you.
But, this is also what every tech entrepreneur will ignore anyway.
This is one of those things that you have to experience a few times before you look back and think 'oh... they were right'. But coding is comfortable and cold calling is very scary. It's also against our nature to ask anyone what they think of your idea, because it might shatter your dream.
YC Startup school nailed this in one of their talks, the presenter opened the talk with something like "this is important advice that you will all ignore, and that's okay, my goal is to make you recognise the situation after you'll inevitably make one of these mistakes".
I'm not being a snob here. Trust me, I made this very same mistake. I ignored all the advice and poured years into building products that nobody wanted.
because all such books are entrepreneurial. this is the sales led approach.
there are other, very valid and successful, approaches. they aren't captured in "entrepreneurial" blogs or books.
Enterprise software rollouts can take months to actually get started from the point of procurement.
This happened at one startup where the sales team bid on a RFP, won, and then had to build it while finalizing the deal.
(First cut ended up being trash and crashed as soon as the customer took it global. It was replacing a paper process and had worked fine in a small scale pilot with one sub org. Customer ended up going back to paper and it took 4 years to rectify and try again)
> By May 2023, ARR reached $200M, and by February 2024, it was $350M
There is little substance about how the invested money was absorbed and how that absorption led to such an ARR. Did it pay for integrations and hand holding for each contract? Or was it used to bluntly bribe the CISOs to use their product?
The open dirty secret of infosec is that outside of authentication systems, the products and services sold do not actually work. Usability and real world functionality are not box-tick items in feature matrix comparison. It is enough that a security[tm] product does something technically correct to get a green tick in the relevant feature list row.
As a result the products are not commonly sold to their end users. They are sold to C-suite, and inflicted upon their victims. And how do C-suite choose what vendor to throw their money at? DDQ/RFx templates. I wish I was joking.
The other dirty secret of infosec is that everyone does their vendor/client/etc. vetting with bingo sheets full of meaningless, context-free questions that try to enumerate SYMPTOMS of different kinds of breach scenarios - they do not attempt to look at root causes, and they certainly do not consider threat models. These bingo sheet templates are used by everyone: vendor teams, insurers, auditors, you name it.
And now we finally get to how Wiz pulling connections intersects with the above. A fair number of the bingo sheet templates come with pre-populated dropdown choices. The choices usually include no more than 8 options, including "Other". The implication is very clear: "if you use one of these known & approved vendor products, then we are fine with it".
Wiz got their offering included in the bingo sheet templates in approximately 18 months from launching publicly. That has provided them with constant advertising from the countless infosec questionnaires thrown around the various industries and the implied checkmark of being pre-approved as a vendor of choice. Given the landscape and the general quality of competing vendors, your product needs to be merely not-shit to stand out and get traction through the various back channels.
Now, from personal exposure I can say that Wiz's product (or at least those I have been faced with) are still better[ß] than their competition. A recent security scan report from a client using Wiz had only ~85% of false positives. The average FP rate for other vendors tends to be 95% or even higher.
ß: security products must be the only segment where vast majority of results being false positives is considered both acceptable and normal. In any other field a product that routinely gets >90% of its answers wrong would be consigned to rubbish heap.
But HTC, Motorola, Waze, Fitbit were definitely not amazing. All sort of died within Google. I guess Waze might have been an acquisition to just keep it from competing, so it was destined to die a slow death.
I'd say the jury is out on Mandiant.
https://www.cbinsights.com/research/google-biggest-acquisiti...
See https://updates.techforpalestine.org/wiz-and-google-the-deal...
I am not an expert at Wiz specifically but I understand this is a "sales lead SaaS business" rather than "product lead SaaS business."
Sales lead Saas companies are incredibly costly from a sales and marketing standpoint, you hire a ton of sales people, BDRs and event marketing and other types of outreach and you fly your sales people around the place to win and dine your customers. So you basically invest all your VC money into your sales organization and it probably takes up 65% or maybe more of your head count. The sales people also take a decent percentage of all the ACV contracts they bring in, thus even if you make a ton of sales, they are not profitable for at least the first year. This is growth at all costs.
> The first sales come from the loyal CISOs who work with the fund.
> This "loyalty program" - which encourages deepening the relationship between the CISO and a party other than his employer - is seen by many in the industry as a red line crossed by Ra'anan and Cyberstarts.
> Cyberstarts vehemently denies [...] and claims that CISOs were never remunerated for purchasing the products of the portfolio companies.
If anything, I'm envious that _I_ don't have access to a system like that (only half joking)
Wow this is huge. Ya I have been feeling this for a while now.
This whole product market fit and things like that are Important, but not as important as connections The way I see a lot of deals going down is the customer will buy the product from that founder No matter what the quality is and that is how a lot of them get high initial.
That is why a lot of VC firms exclusively focus on B2B SaaS these days.
Big Tech acquires companies founded and run by literal foreign spies and recruits said agents into critical positions with their departments. Meanwhile their alumni buddies down the street over at proscribed companies like NSO and Candiru hack into the products and services of these very same companies and use it to target citizens (including journalists, activists, politicians, diplomats) of America and its allies? And no one thinks there is a conflict of interest or threat to national security here?
Looking at wikipedia I also dont know what are their products.
CSPM helps to apply sets of security rules across cloud resources, with the rules usually being based on external standards or custom rules per organization.
It suffers from the downsides of any rules based check system which is that it can be quite inflexible and noisy. Like many security systems it needs to be tuned to the specific environment its running in to be really useful.
What can complicate things is compliance requirements from external or internal bodies that require 100% pass rates or similar. That kind of inflexible approach often just causes needless work and people focusing on the wrong areas to achieve that externally imposed requirement.
I can now say "I know for a fact we have x number of AWS/GCP/Azure accounts that are either not using our IdP or 2A, here's a list" without having to script across multiple cloud APIs
Similarly, I can say "here's a list of people that accessed x resource in the last y days". It really makes my life easier when I want to access metrics about my company's cloud environments
Or is it that it lets you answer arbitrary questions of this sort without having to figure out how to get that data?
If you think about the number of services that AWS/GCP/Azure have, adding good compliance checks across even a portion of those is quite a lot of work :)
A small example from an area I know something about is maintaining the CIS Kubernetes benchmarks (which are used by a lot of CSPM products as a source of rules).
Here you've got the different Kubernetes distributions and then each of the cloud distributions has its own CIS benchmark as the checks are different depending on the cloud in use. Then you have changes over time as different clusters run different versions of Kubernetes, so have different checks. Then you add in that the benchmarks don't release with every new version of Kubernetes, and you can end up with quite a complex matrix of checks.
Consider an enterprise that wants to say "list all the cloud storage buckets we own that are not in the US and are publicly readable and have a name containing 'foo'" - and they have several of each of AWS, Azure and GCP organixations because of acquisitions that aren't fully integrated yet.
Wiz answers that in ~5 seconds, with a rich query language and a bunch of prebuilt rules and detections on top of it, including for tracking compliance with various frameworks.
Maybe it's not written for me.
Could G have _competed_ in the same space without Wiz? Yes.
Could other cloud providers have done the same from a first party perspective rather than rely on a shitty third party product suite? Yes.
"Journalism" like this make me lose faith in this industry. There’s no "secret sauce". There’s nothing special. It’s the same old tired formula that billionaire class have been using:
1) extract as much value from labor
2) prep company for unicorn by getting investor buddies in an investment frenzy
3) buy up other smaller companies to appear bigger
4) then wait for some fossil at big tech to take the bite and reap massive returns for the bois
This is more of a finance bro piece to be honest.