451. Who Wins in the Cat and Mouse Game of Cyber, Open Source’s Role in Security, The Dealflow Network that Sources Deals and Vetts Them, and Will The Future Bring More Bundling or Unbundling? (Oren Yunger)

451. Who Wins in the Cat and Mouse Game of Cyber, Open Source’s Role in Security, The Dealflow Network that Sources Deals and Vetts Them, and Will The Future Bring More Bundling or Unbundling? (Oren Yunger)


Oren Yunger of Notable Capital joins Nick to discuss Who Wins in the Cat and Mouse Game of Cyber, Open Source’s Role in Security, The Dealflow Network that Sources Deals and Vetts Them, and Will The Future Bring More Bundling or Unbundling? In this episode we cover:

  • Navigating Playbooks and Founder Experience
  • Supporting Founders and Cybersecurity Startups
  • Cybersecurity Trends and Open Source
  • Investing in Israel and Tech Hubs
  • Investing Models and Strategic Partnerships
  • Cybersecurity Market Dynamics and AI Impact
  • Consolidation and Best-of-Breed Solutions
  • Identity Management and Deepfakes

Guest Links:

The hosts of The Full Ratchet are Nick Moran and Nate Pierotti of New Stack Ventures, a venture capital firm committed to investing in founders outside of the Bay Area.

Want to keep up to date with The Full Ratchet? Follow us on social.

You can learn more about New Stack Ventures by visiting our LinkedIn and Twitter.

Are you a founder looking for your next investor? Visit our free tool VC-Rank and we’ll send a list of potential investors right to your inbox!

Transcribed with AI:

0:18
Oren Yunger joins us today from San Francisco, California. He’s a Managing Partner at Notable Capital, a growth-stage venture firm where he focuses in cyber security, data infrastructure, and developer tools. Prior to Notable Capital, he was a Chief Information Security Officer at several companies in Israel. Oren, welcome to the show!
0:44
Thanks for having me, Nick,
0:45
yeah, it’s great to have you. I know, I know you spent a couple years in Chicago at the at the University of Chicago. It’s nice to connect with you. Tell us a bit about your backstory and your path to becoming a VC,
0:57
sure. So Nick, I’m an engineer by training. At least, I was never really a good one, so it’s good thing that I was transitioned to becoming a chief security officer and eventually became a VC investor. I spent over a decade in the cybersecurity industry back in Israel, working through different roles in the IDF, financial services and startups. I studied computer science and telviv college and learned and later I in my MBA, as you mentioned at the University of Chicago, and afterwards, I joined GGB capital, which now called notable capital, happy to talk about more about that. And I focus on investing in my cybersecurity, data infrastructure and developer tools.
1:32
Yes, why the rebrand on notable and why the split after 24 years?
1:37
Yes, yes. So after 24 years, with impressive base of LPs, and we invested in us over $8 billion we’ve been fortunate to work with hundreds of founders and companies like affirm, Airbnb, blog data, HashiCorp, Orca, Slack, stock, X, vercel and many more. Political geopolitical landscape evolved so. So did ggV, and last September, we announced a split of the firm, resulting in the formation of notable capital in the US and credit Asia. In Asia, each firm now independently managed its portfolio and based on their geography and notable we continue to focus on backing top founders at seed Series A, Series B, and beyond emphasizing on early stage and our focus are in the US, Israel, Europe and Latin America. We do not invest in China.
2:22
Got it awesome. So tell us more about your thesis and your focus, right? GV, ggV, and notable, you know, broad mandates, multi sector. We even have a co investment, a nice startup out of Boston called fair market. You know, tell us a bit about your focus,
2:38
sure. So notable capital is a US based venture capital firm. We invest, as I mentioned, early to growth and in private companies across two main sectors, cloud infrastructure and business and consumer applications. We’re very thematic and network driven. We go extremely deep, and we try to make decisions extremely quickly in the sectors we care about. For example, we just made an investment a sea stage company building a security data fabric. We’re able to put them in front of 10 different buyers within days to understand what the people who will be consuming the technology think about this opportunity and the team, I guess, more taking a step back. What makes notable special is we’re very thematic. We’re network driven. We have a huge investment in platform and an extremely powerful platform team and very data oriented organization that helps us drive decision we don’t believe in, I guess, playbooks. We have an n type playbook mentality. We think every company is a different snowflake, and we try to be aligning our best to work with our founders in the best way possible. And I would like to think we’re good we’re good people, maybe excluding the person you’re talking to right now, my partner’s colleagues are extremely good people, and believe in notable causes and and the notable companies that and founders will be back. So
3:55
when it comes to not over architecting your investment strategy on playbooks. You know, we have a lot of folks on the show that talk about having a prepared mind. You know, where do you draw that line? You know, where do you prep and kind of understand the landscape you’re investing in without sort of over indexing on a playbook that could get you in trouble? Yeah.
4:18
So obviously there’s kind of the mindset of what we believe in and what we think the world is going but that is, in many cases, driven by the people and the ecosystem that we immerse ourselves in. So it could be founders that we meet, or founders within our portfolio who tell us where they think that the industry is going, and also the networks and the people, the practitioners, that are sitting very close to their keyboard and the keyboard than the problems that they’re facing, and our job is to connect the dots and try to articulate what is, what is the future and how, how it’s going to manifest itself. But it’s important to mention, and I think you touched on it at the end of the day, those technology shifts that are happening all the time that are allowing venture capital to thrive, but the P. People who make those realities are the founders. They have some assumptions and believe and they operate in some sort of ambiguously, and they’re able to align themselves towards the tailwinds that technologies are not allowing them to power through. That’s, I think, what is driving most of our successful investments. You can think of many of the companies that we backed, that have reached success. We, you know, we’d like to kind of tap ourselves on the shoulder. Said that we knew that where it’s going, but the reality is that we didn’t. We had some, perhaps some assumptions, but at the end of the day, the founders who were able to dictate where the company’s going and finding the best opportunities to build a large business, how do you
5:36
think about backing first timers versus serial founders?
5:40
So first I have the pleasure of working with both first time founders and second time even third time founders alike. And, you know, sometimes and or many believe, and I heard it before that, back in the second time founder, especially in the enterprise space, is a no brainer due to the accumulated learnings and and their swift execution. It’s important to recognize that even experienced founders can struggle and break through their previous successes. And one of the most important traits that I think a founder could have is be able to reinvent her or himself every six months or so. This is, this is such an important thing that for a founder to have that mentality, that whatever you learn accumulated, that needs to change, and you need to evolve, to do something unique in the next iteration of the company, whether it’s going from zero to five, from five to 50, from 50 to 250 the founder needs to be able to articulate what is it that they need to do to get to the next stage. And the reality is that many times, second time founders struggle with that paradigm, especially if they sold their prior business before they reach scale, and that’s that could breed problematic if second time founders want to move faster, they hire a team faster, and they have this huge tailwind behind them, and they reach that stage that they haven’t unlocked before, that that could reach some dire consequences. But at the same time, it’s worth noting, the second time founder have the prior with private successful exits, they know how to position their business for a successful outcome, which, which is just a huge, huge advantage, tricky,
7:14
tricky navigating. That is there, is there a way that when you’re working with the serials, and they’re trying to make that jump. And they might may have some preconceived biases, or they may be using tired playbooks from a previous wave of tech you know, if you, if you see the the potential in the upside, is there a way that you, you kind of work with these folks and coach them up in order to kind of help them through their blind spots 100%
7:41
I think a huge mental, mental notice to a lot of great founders is humility and being able to understand what you have not seen before or where you can improve and get better. And the best founders are, as I mentioned, the ones that are able to articulate that to themselves first and to us, the board members, the investors and the rest of the people who surround them later. And so we can, we can put them in touch with people who have unlocked a problem that they’re facing or will face, and are able to learn fast. So that’s you know, every founder, whether second, third or first time, the good ones are able to iterate really quickly, understand that they’re hitting a roadblock or something that is not working, feedback that they’re getting from the market, customers, employees, contractors, whoever it is, and be able to iterate and change those fundamentals back into the business. And so yes, 100% we work very closely with our founders. We have communities that we try to plug them into, and we have advisors that we would draw a lot of inspirations, and our founders are able to draw those in feedback loops as well. Perfect
8:47
Oren, you’ve talked about the two big equations that startups must get right. One is focused on revenue and buyers, the other on talent. How do you help founders with each
8:59
so notable, our mission is to empower founders and help them drive success in their businesses. We have talented and experienced platform team, as I mentioned. We’ve developed impactful programs like founders and leaders, which is a proven management training curriculum that is accessible across our portfolio. We provide dedicated support in talent acquisition and offer strategic guidance on revenue growth, including critical networking opportunities we have. We have a cohort for product leaders. We have cohorts for good market strategies, and as I mentioned, approach or anti playbooks designed specifically for each company in sector, in the stages and use unique circumstances that they’re sitting in and recognizing that every business is just a distinct business and requires customers solutions. We help many companies with introductions to buyers and operators, but we over rotate on talent. Great teams make great companies full stop.
9:52
Oren, you published a list of the top 30 cybersecurity startups in June of this year, a list nominated by V. VCs and voted on by CISOs, what primary themes emerged from this effort? Yeah,
10:05
so we did, and thanks to my colleague Laura, who initiated and catalyzed this initiative, we celebrated a rising in cyber the project in the New York Stock Exchange two months ago. And as you mentioned, we really wanted to dive into what are the real problems that security leaders are facing, and we surveyed over 100 security leaders that revealed three innovation drivers that are needed by security teams to adapt to the growing footprint of technologies, AI and sophisticated cyber attacks and kind of the three buckets that were emerged our first one is identity and access management does increase demand in next gen Identity Governance and administration, new authentication methods, privileged access controls and specifically to human and non human identities. The second bucket is cloud security. The CISO needs innovation in cloud detection and response, data security automation, risk management and AI threat detection, and the third bucket is application and code security. And we see startups that are enabling collaboration between developers and security teams, that are leading the way with open source security and AI tools, that are improving code remediation and testing, which is phenomenal to see how AI is injected into cybersecurity and able to catalyze businesses to do, to do more, to do more with more, or do more with less. Do
11:24
you think the bigger cyber related companies that are built in the next five years will be more open source based or or not? Open
11:33
sources is something that is fundamentally helping the technology industry. Open source libraries are implementing in every single piece of technology that is running today, and it’s very important now with regards to how the distribution model will work for security businesses, whether they’re going to be closed source or open source, this is, this is a different question. I have to believe that with the top five companies in the cybersecurity today, and even the top 10 most valuable cyber security companies today being closed sourced. I have to believe that this will remain the paradigm. In fact, I have not seen a ton of open source security companies, but we’re seeing more and more solutions that are enabling security teams to do to do their jobs faster, and are coming through the distribution of open source. One of the companies that we backed at series A is a company called HashiCorp, which is a developer focused but very security oriented company. And they and one of the most popular solution is Vault, which is an open source solution, but it adopted but by a huge number of the Fortune 500 today,
12:43
or investing in Israel has has changed since October 7. Are you still actively investing in the country? And you know, how have your efforts changed in, you know, the recent past year?
12:56
Yeah, thanks for asking about that Nick. You know, I was born in Israel. Still have family in Israel, a lot of friends, and a great believer in the ecosystem. And so this is, this has been, you know, traumatic event, not just for the ecosystem in the country, but but for me personally, the founders and employees have been attacked. Personally, the country and the tech ecosystem are extremely small. There’s almost no degrees of separation, and this has affected 100% of the population. So I know a company whose CTO was was murdered through the actions of October 7, which is, you know, devastating for founders on a personal front and the company front and employee front, there’s been so much to manage while the company is is reeling through such a painful and unprecedented time. And it took some the industry some time to get out of this shock, and then they rebounded. It rebounded as fast as anybody could have hoped. To be honest, startups are shipping code, closing new businesses, and they’re doing better than than ever before. I you know this is something they have something to prove they want and they need to win. I don’t know many, many founders who are shipping code through, you know, but Well, being at reserve and so that kind of tells you something about their mindset to dedication to what they’re building. So I greatly admire the Israeli entrepreneurship mindset. The Israeli founders have proven to be able to adjust and iterate quickly. I’m extremely excited to keep backing Israeli founders. And, you know, we just came back from Israel just a few weeks ago, and we’re going back again in October. This does not change our calculus at all. We have been going to the country every quarter, and we can continue doing so until somebody is going to it’s going to stop me physically. Wow,
14:37
you know, Oren, we saw this, you know, since Eileen Lee’s unicorn report back in 2013 at the time, 80% of unicorns had been founded in the Bay Area. And since that time, we’ve seen this Cambrian explosion across the states. You know now that shifted. It’s right around 80% are founded outside of the Bay Area. Have you seen something similar in Israel? You know, I’m curious if other tech hubs, like Jerusalem, etc, have emerged, or if it’s still really, you know, Tel Aviv centric.
15:10
Yeah. So I guess everybody who listens to me now that is in Israel, whether it’s in the north, the south or, I guess, closer to the Jerusalem is thinking, Hey, is he going to recognize so the answer is that more companies are being built outside of Tel Aviv, but the reality is that the center is still the powerhouse, and it’s delivering the most, the biggest returns and startups, and perhaps that’s because of talent concentration. Most of the country is centered around Tel Aviv, and that’s where young people want to come and work. That’s where people served in their military lives, and that’s, that’s kind of where the big metropolitan area in the country. So we see, you know, within perhaps a three mile radius, I’d say that you would find 98% of value created in the country. So this is highly concentrated, highly connected ecosystem. And I while there are some incredible efforts, like a nonprofit called place IL, which is which is helping not just organizations, but people who are in the periphery, periphery, get into technology, and they’re doing a great job, but as as kind of, if you look into the near future, I’d say that the telvite would still be the center
16:25
of gravity. Well, I don’t have the stats in front of me, but I think the listeners are pretty familiar with the fact that Israel punches well above its weight per capita. I think from a venture backed exit dollar standpoint, it’s even that’s even better than the US, which is a staggering Oren. You have a unique investment model. Can you talk about your efforts at svci and invest in data and how it’s unique?
16:51
Yeah. So as part of my work at notable I was able to help and design new investing models that are deeply embedded in the professional tech environments, and they create unique series of wins. And so svci, which stands for Silicon Valley’s CISO investments, in a nutshell, it’s a group of 60 chief security officers that operate as an angel syndicate. The goal is to fuel the next generation of cybersecurity innovation the group or individuals within the group identifying problems in the security market and pursue startups that are solving these problems in unique and defensible way. And the group invest behind those startups. They support in the product, advice and positioning, marketing, applications and and they help but win. The group is extremely active. They communicate. We communicate over slack, and everybody contributes to the conversation. We don’t we don’t have slackers. We don’t have people that are pretty faces on the website. Everybody contributes. Everybody works. And they source great companies, and they help diligence them. And this is what creates an ecosystem that everybody benefits. The founders, from having a strong advisory and product leaders they see so from shaping the future of the industry that they really care about and us, you know, we were small beings in this ecosystem, and we love to be flying the wall and seeing how smart people are interact with new solutions. We’re lucky enough that we get to build good relationship with founders and potentially invest in their future rounds and some really great companies that this group was able to back, whether it’s with notable or without notable is you know, Jada encode Island, Endor Orca. Those are great businesses that we founded when they had, you know, we funded when they had barely any customers, if customers at all. And that is just an incredible ability for this group to identify something that is, you know, where the puck is going, and invest behind it and really diligence this landscape of imaging technologies and founders in a unique way. Now, just to kind of finalize with invest in data or IID, which follow the footsteps of svci, again, it’s an angel syndicate that’s comprised of 50 leading data executives in in the US. And the world of data is just immensely rapidly changing, and the role of chief data officer is rising and setting strategies behind AI adoption and connecting the business with technology. And the group comes together to invest in support early stage startups, and we believe are pushing the frontier of innovation and data. So the synergy between svci, ID and notables is pretty clear, and even though we spend a lot of time with those groups, we get to see and be part of this builder ecosystem, and connecting some assumptions of technologies and builder in the tech, and helping both sides influence one another and just to get better. So if we do our job right, we’re able to connect the dots and and get better than anybody else in this industry. Yeah,
19:34
I want to underscore the power of this strategic approach to approach to investing. I’ve spoken with a number of other investors that have things that rhyme with this. And you know, it’s, it’s not a brand new concept, but if you have a constituency, in your case, CISOs, and they’re the ones getting pitched by all these emerging startups, you know you’ve got deal flow, right? If you encourage them to put it into the pipe. So whether they like it or not, you’ve got deal flow, and then you also have your diligence team, right? Like the folks that are going to be purchasing this are probably in that group, whether it’s an SMB product or an enterprise product or a certain type of, you know, security architecture. So anyway, I, you know, I’ve spoken with a number of groups that that do similar things, not in the CISO camp, but I think it can be very powerful if you get the flywheel spinning and if you get the constituents activated, you know. So speaking of cybersecurity, Oren, you know, it continues to be a hot sector, but a lot of consolidation is happening. Is this good for founders? Is it good for VCs? And how do you advise companies?
20:44
Yeah, we invest in a company. Our diligence stresses the potential to take a company public as the outcome, and we’re looking for home runs, and we make sure to set expectations with our founders. This is this what we want to do? At the same time, we recognize that building a company is just not a straight line into the right and there are a lot of things that are happening with the company, happening with the market, and from the time we invest, and having the M and a market where incumbents understand that they need to innovate helps create a vibrant ecosystem that is serving startups and the companies and the buyers who want tools to work with one Another, and of course, helps the investors. So my advice, you know, to founders, is, aim high. Go after big and ambitious goals. Things are things are nice to have, or features of bigger platform might not make it as independent business.
21:33
I mean, we’re going through this incredible change at the moment, right with AI, moving from a lot of logic based to a lot of observational you know, technology is that is this just fundamentally upending a lot of the tried and true architectures for cyber?
21:51
AI is affecting cybersecurity and the way, I don’t know if the same way, but it’s affecting many industries, including cybersecurity. And I see this affecting cybersecurity in kind of two ways. One, you can think of AI as producing new risks. For example, there’s a risk that cyber criminals are able to manipulate or create unintentional negative impact or use of AI to create more sophisticated, highly, high velocity attacks on organizations, or change the AI models that organizations are relying on to drive their decisions or interact with their customers, both are very bad, negative impacts at the same time, AI is a great catalyst for security products. It increases their ability to process and quantify data and help security analysts be more productive, help them with vulnerability remediation, as well as to, you know, secure development life cycle, and the positive opportunities of AI in the security industry are just immense. And I’m, personally, I’m super excited about, you know, the next generation of cyber security innovations that are injecting AI into how the product works, how the product teams are interacting with, with with the products, and are just creating larger and larger businesses. So fairly optimistic of how AI is affecting this industry.
23:05
You know, cyber is a bit of a cat and mouse game. Do you feel like the advances in AI are better for the cats or better for the mice?
23:13
I’m an optimistic guy, you know, I see AI as a positive more than a negative. So I’d say that I’m on Team cats,
23:20
the cats, I’m thinking, maybe it’s maybe it’s the ones that preside over the home where the cats and mice fight. But nevertheless, enterprises spent 13% of their IT budgets on cybersecurity in 2020 that rose to 21% last year. Where will the percentage of spend be in three to five years from now, Oren
23:42
so I would, I would estimate the cybersecurity spending could reach 30, even 35% of IT budget within the next few years. And the integration with it and security is becoming increasingly evident that organizations are prioritizing safeguarding reputation, customer data and building trust and stimulus. The investments in it efficiency are allowing businesses to allocate more resources towards robust cybersecurity measures and aligning with the evolving regulatory and operational demands. And we’re also been observing the evolution of the IT and security dynamics. And in the past, you had this role called Chief Information Officer or CIO, which lead technology in general, which is including cybersecurity, and today, it is the reverse. The shift underscores the growing importance of cybersecurity as a strategic investment, essential for maintaining resilience and the competitive edge in a digital first environment. And just lastly, security is a zero sum game. Companies just cannot afford to get breached. Do you
24:42
think we’ll see a cyber company in the Fortune 10 in the next five years?
24:46
Yeah. So as much as I’d like to believe and hope, the answer is no, I don’t think just yet, cybersecurity is attached to technology and technology investments, and any new evolution in tech opens the door for new. Attack surface and requires the relevant mitigation cybersecurity damages expect to cost the world over $9 trillion this year. That’s that’s what a T and the awareness of security is constantly rising, and companies cannot do business without significant investment in the field. So huge amounts of revenue coming from the top three cloud providers as a result of security and trust they created and continue to invest in. So with all that in mind, I think it is a matter of time before we see cybersecurity companies rise to the top of the Fortune list. But you know, it will take it more than, more than three to five years.
25:35
Is the Google and Wiz deal dead at this point? I mean, is that over? And will we see more large technology incumbents trying to pick off, you know, high flying emerging cyber companies.
25:48
I think, I think that deal projects, that this is just an important, hugely important ecosystem, and and companies, huge companies, can be built here very fast at the same time. It’s important to note what Google is trying to do, which is capture more cloud mindshare from the other cloud providers, and you can see how cybersecurity is influencing decision makings of enterprises. To say where I want to align myself. Do I want to work with Microsoft, Amazon, or can I work with Google? So and if you need to scratch your head and say, Well, Google is not providing security in the right level, then, then you can justify why making that huge price on a security company to balance that playing field could really, could really make sense. And so, yes, security is just a huge part in decision making of organizations. And you can see that as well with the AI deployments. You ask any VP engine CTO, not just security teams, but the people who actually use and are in charge with deployment of AI models, you ask them, What are the biggest challenges they have in front of them? And they would tell you this is, you know, the security challenges of trusting those AI models, making sure that they they ingest the right information, they spit out the information that we intended to and that is just something that needs to be solved. And reinforces the fact that security is just a huge catalyst and importance with delivering any type of technology shift, what
27:20
areas within Enterprise it do you think are most vulnerable and most exposed to attacks? And why do you think those attack vectors are so hard to protect?
27:31
I’d say three areas that are I’d say in enterprise IT are vulnerable to attacks. The first one is cloud services. In the good old days, you had a PC and a server, and that was a lot easier segment to segment and protect. And with the move to the cloud, you see new vectors of attacks in the wild, the footprint is growing exponentially, and traditional firewalls just don’t work. Security has moved from place of saying no to saying yes and later protect, and the stats show that about 75% of organizations Experience cloud data breach due to misconfiguration or unauthorized access, and cloud environments are complex and require robust security measures and safeguards against attacks. So back to the wiz deal. That’s just a huge, important area where investors in a company called orca security, which is seeing huge tailwind in this industry because of cloud services are just a huge, important factor in enterprise IT. Second bucket is applications. So everything is code. Every company is becoming a technology company and AI with AI, things are moving faster, and it’s hard to keep track of every single line of code and make sure they cannot introduce a threat or a backdoor. And AI is making things harder, where not only the inputs need to be protected, but also the outputs that become something of a black box, then organizations need to understand if the AI isn’t providing incorrect or improper information back to the user, the last bucket is third party risk. So organizations are increasing, increasingly relying on other vendors to provide services. You mentioned, open source libraries 100% whether it’s HR systems, finance, hardware components for a new car, it is very difficult to know in the real world or in real time, what are security measures that each one of those vendors in the hundreds of connections and 1000s of vendors and enterprise are leveraging so all in, you know, these are kind of threats areas that I see challenges in growing complexity, interconnectivity and evolving in kind of the cyber attack landscape, and effective cybersecurity strategies must be developed to address and be more proactive in those domains.
29:41
Oren, how will go to market in deployment of cyber products evolve in the coming years? You know, will we see MSPs and mssps with a larger or smaller presence in the market?
29:51
And in the coming years, the evolution of security go to market and deploy and strategies will likely see more MSPs and MSS. Is maintaining and expanding their market presence. There’s a shortage, shortage of security talent, with cybersecurity threats growing in complexity. Organizations are increasingly reliant on MSPs and mssps for specialized expertise of 24/7, monitoring, rapid incident response capabilities. These these providers are well positioned to offer scalable, integrated security solutions across diverse IT environments, including shift shift towards cloud or hybrid IT environments, and this trend underscores their role in addressing the evolving needs of businesses. And dynamic landscape are
30:34
the range of offerings overwhelming today’s CISOs and CSOs. You know, will we see more consolidation and more bundling, or more adoption of best, best of breed point solutions?
30:47
Yeah, this topic has been discussed. I think Palo Alto Networks reached that topic in one of the last earning calls. The array of cyber, cyber security offerings can, can indeed overwhelm CISOs with, you know, many of them feel overwhelmed with the multitude of technologies that they need to integrate to look at but looking ahead, we’re likely to continue seeing the tread towards consolidation and bundling of cybersecurity solution. This approach offers more holistic platform that simplify the management and the connectivity between the solution and addressing challenges effectively. However, the adoption of best in breed point solutions will continue to niche threats or advanced capabilities that are not covered by integrated platforms. So there’s kind of a balance that needs to be striked between consolidation and leveraging specialized technologies that will be crucial to maximizing security effectiveness in this evolving landscape. With that in mind, I’d say that this is why founders in the cybersecurity should, should only go after meaningful problems that are not nice to have in our building, really meaningful platforms. I mentioned orcas security performed that before that’s that’s a that’s a platform that started with identifying vulnerabilities and expanded to helping organizations mitigate those solutions, mitigate those vulnerabilities that they see, consolidating them, shifting left to the application, shifting right to more incident response, and are really becoming a platform solution that and this is the opportunity for a lot of those solutions as they grow and expand and see the landscape. We’re also investors in a company called drada, which is building trust trust and expanding from a stock to management solution, from building compliance to more third party GRC privacy type solution, and are really seeing huge tailwinds that are coming from consolidating in those areas
32:32
we touched earlier a bit on access control. I’m curious to get your your input on identity and the future of identity management. You know, what does that look like in the next 10 years? 15 years, you know, in this online explosion of deep fakes and bots and thieves impersonating others online? Yeah,
32:53
I think deepfakes is a huge problem that the world is only starting to face and see if somebody is creating a convincing deepfake of Elon Musk announcing a significant financial move of purchasing, I don’t know, a billion dollars worth of dodge coin. What is that? What is that going to create? What type of effects we’ve already, you know, witnessed some, some disgruntled ex employee using voice cloning to manipulate trading desks and leading to financial losses or a fabricated video of tarnishing CEO’s reputation. So so we’ll see scammers to explore deepfakes in technology and deceive financial institutions to transferring large sums of money. This is, this is going to be a huge problem on our industry. I think in order to resolve something like a deepfake, you need to have a different, different change in paradigm altogether, I think the internet, and this is something that there’s a great, there’s a great, great lecture that a friend of mine, Caleb Seema, put together about this, about this problem. And I subscribe to this, to this notion that you need to have a fundamental change in the way we authenticate individuals. And the current way to authenticate was built in the more traditional, not online world, and you need to make a big change in infrastructure to make sure that people can authenticate in kind of the digital world. What you’re doing, how do you enter financial institutions? How do you shop in E commerce, what is permitted, what is not, and kind of sign that if you produce a news article, this is attached to an individual and not just some random, anonymized information that is eventually being consumed on Twitter. So there’s a huge paradigm shift that is happening. There’s companies that are helping identify against deepfakes, but I think that this is a substantial paradigm shift that we will see coming together in the next few years. It’s pretty
34:44
scary, especially with you know, you hear about all these scenarios where the aging population has been fooled into transferring their life savings away, you know, to somebody that sounds like their son on a phone call and. Since we have an expanding, aging population here in the US, it’s, you know, there’s a lot of folks out there that don’t have the protections that maybe the enterprise does, and it’s a bit scary to think about how technology can be used to, you know, to take advantage. I agree,
35:16
yeah, we’re seeing a lot of, a lot of changes. I think this is something that’s unique about cybersecurity landscape. It’s evolving. It’s changing with every paradigm shift. So that’s security that needs to protect
35:28
it. So Warren, recent news, you know, CrowdStrike, not the kind of news you want, you know, to be on the front page. But it wasn’t for the reason that maybe people initially thought, at least I thought, you know, there was a cyber breach of some sort. It turned out not to be that, but it does make one think, you know, and in the next decade here are we going to see this sort of thing happen on an even bigger scale? You know, will entire governments be shut down for extended periods of time due to cybersecurity attacks in an era of pandemics, nuclear weapons and climate change is our you know, cyber breaches the single greatest threat to humanity. First of
36:04
all, it’s worth noting that what happened with Crosstrek was not a cybersecurity attack. It was it was a fault, an incident, and it was improper testing and deployment of security products, but it was not a cyber attack, and for I experienced it personally. I was at New York airports for a few good hours, seeing all the blue screens and actually being having had had some issues getting into the country because the the TSA portals were down. But to our question, you know, is this type of incident can can happen more? Perhaps it was a good thing that what happened in such a large scale happened without a security attack factor behind it, because now people understand how much impact third party components, third party technologies, have on on everything, on the way we operate, and what devastating consequences could happen when a piece of technology is not operating properly, and I’ve already talked but a few chief security officers in large fortune 500 organizations who have been given the mandate from the board to build teams that are focusing on resiliency. And how do you how do you build software in a way that you can continue with with something like this happening, with regards to cybersecurity attacks driven by governments and statewide attacks. These, these, unfortunately are happening. And you know, we’ve seen successful attacks cripple large water supply, electricity, oil and gas, and really disrupt communication, compromise initial security, leading to prolonged shutdowns and kind of taking a lot of time to be for the system to be restored. We’ve seen in 2015 Russia attacked Ukraine’s power grid, eliminating power for close to half a million residents, and also SolarWinds hack that demonstrated how deeply cybersecurity attacks can infiltrate governments, or how motivated they are to attack a piece of software that can affect governments. So these scenarios underscore the urgent and urgent need for robust cybersecurity measures and intentional cooperation to prevent and mitigate impact of cyber threats on government operations for sure. Oren, if
38:21
we could feature anyone here on the show, who do you think we should interview and what topic would you like to hear them speak about?
38:27
I think you should interview Omri Caspi. He’s the first Israeli NBA player. He played for the wars in their championship year, and he became a venture capital investor in Israel. His go to market and value add is quite simple. Is he’s very, extremely likable and respected by founders, and he uses a celebrity star power to hustle and connect them with industry experts. I think he’d be a fascinating person to have. Michelle perfect
38:52
Oren, what book, article or video would you recommend to listeners? Um,
38:57
if it’s okay, can I share a podcast I recommend? Yes. Okay, so I really like the founders podcast by by David senra. David is doing it. I love listening to stories and incredible leaders and how they translate to modern founders and companies. Personally, I, you know, I would start with Napoleon episodes and just, just a ton of learning and wisdom to learn from, from somebody who lived, you know, so many years ago, and how they apply to startup founders even today.
39:27
I will second that that recommendation Oren, do you have a any habits, tactics or techniques that are a force multiplier? Yeah,
39:35
I think people would describe as persistent, maybe tenacious. I spent a huge chunk of my waking sometimes sleeping hours, thinking about how I can help portfolio companies that I work with, I’d say that I’m a people’s person, and one of my top fashion is connecting people and dots, so much so that you know, portfolio founders are getting can wake up one morning and getting 10. New introductions to things that I think would be useful for for their companies. So I think that that’s something that has been has been helpful and sometimes described as Oren led growth, in some instances,
40:11
perfect. And then finally, here Oren, what is the best way for listeners to connect with you and follow along with notable
40:16
so it’s a cliche but, but a true one. I get many emails of funding requests in a day. I work very closely with networks of individuals and founders who I trust. So you can send an email to me directly, but, but if, if you impress one of the people that I work and trust very closely, you’re very likely to impress me very good.
40:38
Well, he is Oren younger, the firm is notable capital Oren. Thanks so much for all the insights on cyber and and tech and AI and beyond. Today really appreciated the conversation.
40:50
Thanks so much for having me. Nick
40:57
All right, that’ll wrap up today’s interview. If you enjoyed the episode or a previous one, let the guest know about it. Share your thoughts on social or shoot them an email. Let them know what particularly resonated with you. I can’t tell you how much I appreciate that some of the smartest folks in venture are willing to take the time and share their insights with us. If you feel the same, a compliment goes a long way. Okay, that’s a wrap for today until next time, remember to over, prepare, choose carefully and invest confidently. Thanks so much for listening.