On Security (a podcast powered by tact.)

Tact IT

Where cyber security founders, investors, sellers and operators talk. One guest per episode, one journey. How they built it, backed it or sold it, the mistakes they made and the advice they'd give anyone on the same path. Hosted by Jack Brandwood. New episodes weekly. Watch on YouTube: https://www.youtube.com/@startandscale Follow on LinkedIn: https://www.linkedin.com/company/start-and-scale/posts/?feedView=all

  1. 2d ago

    Seth Spergel (Partner, Merlin Ventures): What to Ask a VC Before You Take Their Cheque | S6 E6

    🎯 Building a product has never been cheaper. Seth Spergel thinks that changes what decides who wins. He has sold most of his first fund’s portfolio, and two of those companies went to Palo Alto in the same week. His view is that agentic coding has brought the cost of building down so far that the product on its own rarely settles anything anymore. What tends to settle it is who gets out in front of the market first, raises the money, and buys enough runway to build the rest. He points to the CSPM market as the clearest recent example, and most of this conversation comes back to that idea in one way or another. 🎙️ What to expect in this episode: • Why Israel keeps producing cyber startups and most countries don’t. It comes down to people leaving service as a cohort, older founders mentoring the next intake, and a handful of seed funds set up for exactly that stage • Money is cheap for the best companies, so the question to ask before you sign a term sheet should go to the VC’s portfolio founders rather than the VC • The traction slide that worries him. When every early customer turns out to be the founder’s neighbour, uncle or dad’s old roommate, he wants to see whether they can sell somewhere nobody knows them • Why the seed round in Neo Security was really a bet on Nick Warner, who took SentinelOne from around $5M to a $500M IPO and Cylance from nothing to $200M and a billion-plus sale • Nobody running a security team is going to buy ten separate AI security products. His take on where consolidation lands, and why every startup still needs to win one entry point first • When to make the first go-to-market hire. His answer is months in, not at Series A, even if you have to pay them a draw because there is nothing to sell yet • Government being ten years behind industry is a myth in cyber. The intelligence agencies adopt security tech earlier than most companies, and what he calls the Sunday Monday problem is what actually costs them people • The Dig Security story. A quarter of a room of CISOs asked to meet the founder, he tracked competitors’ hiring by role, and when he was nudged towards AI security, Palo Alto later cited it as a reason for buying the company • The Mom Test. Why asking “Do you like it?” gets you polite lies, and what to ask instead 👤 About Seth: • Managing Partner at Merlin Ventures, a seed-stage cybersecurity fund he started in 2018. He is based in Washington, D.C., and his partner Shay Michel runs a team of seven in Tel Aviv. The fund backs early-stage Israeli cyber companies and helps them break into the US • The first fund made around 15 or 16 investments between 2018 and 2024 and has sold most of them, including Dig Security and Talon, which Palo Alto Networks bought in the same week. Merlin also led Torq’s Series D. In late 2024, he raised an $85M seed fund with outside LPs and has backed eight companies from it so far, including Neo Security alongside Andreessen Horowitz and Craft • Before Merlin, he was at In-Q-Tel, the venture arm the CIA set up to work with the intelligence agencies. Before that, he was VP of Engineering at ThinkGeek and took it through its IPO, after more than ten years at IBM in development and sales management Merlin runs a community of several hundred CISOs and an annual event in Denver, Merlin Safari, which had 150 people and around 70 CISOs this year. 🔗 Seth Spergel: https://www.linkedin.com/in/sethspergel/ 🏢 Merlin Ventures: https://www.linkedin.com/company/merlinvc/ 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎧 Spotify: https://lnkd.in/eij7j2m 📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/

  2. Sep 25

    Justin Woody (Co-Founder, Twine): Nobody Will Ever Hire Enough People to Fix Security | S6 E5

    🧩 Security tools don’t reduce work. They create it. And nobody has the people to do it. Justin Woody spent six years at Claroty hearing the same feedback on a product that scaled to $100M ARR: great dashboard, no one to act on it. So for his next company, he asked strangers to rip the idea apart. Every one of them said the same word: identity. What to expect in this episode: • Nobody is ever going to hire enough people to clear the security backlog. Why the fix sits between the tool stack and the human, not in another hire • Why a teaching hospital ends up with 20 identity tools, a $3M IGA on top, and people as the glue holding it together • The “don’t be nice” test: why validating with friends is an echo chamber, and how friend-of-a-friend conversations killed the idea he wanted to build • Digital employee versus AI agent: one reports back to one person, the other learns the tribal knowledge, the VIPs and the third-party contractors • What it should take before an AI gets to close a ticket without asking: approval per action, read-only until trusted, a full audit trail • Coming out of stealth with $12M: why being the only one talking about it worked, and why there are now four or five direct competitors and 50 within a degree • Token costs, on-prem LLMs and measuring AI on business outcomes: the three themes he heard across Black Hat and AI4, and why he thinks the token panic is a crescendo effect • The security team of the future: five or six digital employees each, a command role, and a KPI on every one because they cost money to run About Justin: • Spent six years at Claroty as Director of Innovation, then Senior Director of Strategy and Research, joining when the company was around two years old and staying as it grew to $100M ARR • Before that, led the IoT/OT practice at Mandiant Managed Defense and spent over a decade at IBM in security delivery and consulting • Co-founder of Twine Security, building AI digital employees for cyber teams. Came out of stealth with a $12M seed round; the first digital employee, Alex, works on identity 🔗 Justin Woody: https://www.linkedin.com/in/jwoody1/ 🏢 Twine Security: https://www.linkedin.com/company/twinesecurity/home/ 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎧 Spotify: https://lnkd.in/eij7j2m 📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/

  3. Sep 18

    Patrick Dillon (CRO, Nudge Security): You're hiring the wrong sales leader | S6 E4

    🚨 Most sales leaders forecast their quota. Patrick Dillon calls that a recipe for disaster. He has scaled cyber go-to-market teams from under $50M to $150M, and he's blunt about what breaks along the way: hero CROs, copy and paste playbooks, bloated sales teams, and founders who can't let go. What to expect in this episode: • Why a CRO who has to personally rescue deals is running a hero strategy, and why it fails • 8 reps doing the work of 20: AI deal scoring out of 100 at every stage, and zero early-stage deals in the forecast • Founders: if you're chasing your first 10 to 20 customers, you don't need a CRO. Hire a VP of Sales • Series A money is go-to-market money, and what investors expect to see as a company moves from seed to Series C • Shadow AI is infinitely scarier than shadow IT: your existing tools are switching on AI overnight and nobody approved it • If blocking and alerting worked, cybersecurity would have been solved years ago • What he hires for: grit, humility, three to seven year tenures, and candidates who ask five good questions About Patrick: • Chief Revenue Officer at Nudge Security, brought in to scale go-to-market after its Series A • Previously CRO at Airlock Digital, plus senior go-to-market roles at Saviynt, BeyondTrust and Hewlett Packard Enterprise • SVP for the Americas at Saviynt through COVID, building the team over Zoom while the company went from under $50M to $150M in revenue in three years • Started in recruitment at Robert Half in 1998 and interviewed thousands of people before he ever sold cyber 🔗 Patrick Dillon: https://www.linkedin.com/in/patrickdillon2/ 🏢 Nudge Security: https://www.linkedin.com/company/nudge-security/home/ 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎧 Spotify: https://lnkd.in/eij7j2m 📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/

  4. Sep 11

    Matan Bar-Efrat (CEO, Rein Security): The chatbot gave us their API key! | S6 E3

    At Black Hat, Matan Bar-Efrat's team took over an AI shopping assistant by talking to it. No zero days, nothing sophisticated. The chatbot handed over its API key, and the guardrails built to protect it fell to the same manipulation they were meant to stop. This episode is about what securing AI agents actually takes once they're running real business processes. Covered in this episode: • The Black Hat "Bye Bye" demo: owning an AI shopping agent through conversation alone, and why the guardrails failed • Why prompt-inspecting "guardian agents" catch the easy attacks and miss anything even slightly sophisticated, and why watching the actions an agent takes is how it should be done • The exploitation window collapsing from months to basically instant, and why signature-based controls and patching cycles were already losing • Enterprise agents moving from copilots to running business processes, why finance and insurance are first, and why that shift is what has to justify the trillion-dollar AI valuations • The founding story: investors calling the idea dumb, why he says that was good, and his advice for founders: talk about what you don't do, because doing everything is doing nothing About Matan: • Co-founder and CEO of Rein Security, the enterprise agent security company, launched with an $8M seed led by Glilot Capital and backed by founders from Aqua Security, Orca Security and Talon • Former Unit 8200 officer, in cybersecurity since he was 18 • Spent seven years at Cyberbit, ending up running its Northern European territory, before it merged into Elbit • Presented the "Bye Bye" AI shopping assistant hack at Black Hat and recently spoke at a JP Morgan fireside on AI agents in front of 1,200 people 🔗 Matan Bar-Efrat: https://lnkd.in/egC5jjwD 🏢 Rein Security: https://lnkd.in/ebnCUi39 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎧 Spotify: https://lnkd.in/eij7j2m 📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/

  5. Sep 4

    Ely Abramovitch (CEO, Legion Security): Your SOC Isn't Ready | S6 E2

    The Hugging Face and OpenAI incident put 17,000 alerts through the SOC in a few hours, most of them low severity detections nobody would normally look at. Ely Abramovitch’s read: it felt like a million stupid attackers, and the next one arrives with actual malice, against a company of consequence. This episode is about what security operations has to become before that happens. Covered in this episode: • How Microsoft Sentinel went from zero to $1B in ARR, and why almost everyone inside Microsoft objected to it until the revenue started piling in • Why SOAR failed as a market, and why “alerts automatically closed” and MTTR are the wrong scoreboard for a SOC • Why most AI SOC solutions are going about it the wrong way, and why watching how your team actually works is how it should be done • Why security orgs are collapsing into three layers, sensors, agents, people, and why 40% of Legion’s revenue is already outside the SOC • The founding story: quitting Microsoft before any term sheet, a seed signed two to three weeks later, his take on what made Wiz special, and his advice on founder mental health About Ely: • CEO and co-founder of Legion, the AI SOC company that came out of stealth with $38M from Accel and Coatue • Led product management for Microsoft Sentinel as it went from zero to $1B in ARR • One of the first employees at Indegy, acquired by Tenable • Started out as a jazz pianist in New York, studied maths and philosophy, and served in army intelligence, where his work was awarded the Defense Prize. 🔗 Ely Abramovitch: https://www.linkedin.com/in/ely-abramovitch-a3a912bb/ 🏢 Legion Security: https://www.linkedin.com/company/legion-security-ai/ 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎧 Spotify: https://lnkd.in/eij7j2m 📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/

  6. Aug 28

    Howard Ting (CEO, Opal Security): Why AI Agents Break Identity | S6 E1

    Ask any attacker the best way into a company: compromise an identity. 26 years into cybersecurity, Howard Ting says the problems he worked on at RSA in 2000 are still unsolved. This episode is about why, and what AI agents are about to do to the identity stack. Covered in this episode: Why standing permissions are still the easiest way into an organisation, and why nobody revokes access once the need expires Rubber stamping: what actually happens when a manager faces 100 access requests every morning Why agent access decisions will run a million to one against human capacity, and why AI narrowing the funnel is the only way through How Opal's Paladin agent reads tickets and Slack context to cut the review volume going to humans by 95 to 99 percent How Howard picks companies (80 percent of the decision is the market) and his three S's framework for career growth: scale, space, scope About Howard: • CEO of Opal Security, the Greylock-backed access governance company • Started in identity at RSA in 2000, launched Microsoft's identity federation product at Bill Gates' last RSA keynote • Joined Palo Alto Networks at roughly employee 60 and Nutanix at roughly employee 40. Both grew from a couple of million in revenue to a billion, with an IPO at each • Five years as CEO of Cyberhaven, worth $1B when he left • Now back in identity to work on what he calls unfinished business 🔗 Howard Ting: https://www.linkedin.com/in/howardting/ 🏢 Opal Security: https://www.linkedin.com/company/opalsecurity/ 👤 Jack Brandwood: https://lnkd.in/dFMyDUEN 🎵 Spotify: https://lnkd.in/eij7j2m 📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/

About

Where cyber security founders, investors, sellers and operators talk. One guest per episode, one journey. How they built it, backed it or sold it, the mistakes they made and the advice they'd give anyone on the same path. Hosted by Jack Brandwood. New episodes weekly. Watch on YouTube: https://www.youtube.com/@startandscale Follow on LinkedIn: https://www.linkedin.com/company/start-and-scale/posts/?feedView=all