Cult Products · 2026-03-31 · 38 min
Key moments - from our scoring
Substance score
66 / 100
Five dimensions, 20 points each
Entro addresses a critical gap in enterprise security: the discovery and management of non-human identities (machine credentials, API tokens, service accounts) and AI agents that now vastly outnumber human identities in organizations. Itzik Alvas, former CISO of Microsoft Defender Cloud and a healthcare company, experienced breaches involving non-human identities firsthand - the motivation that led him to co-found Entro with Adam, a former Broadcom executive. The core problem is stark: his customer base shows an average of 144 non-human identities per human identity, meaning a 1,000-person company manages roughly 144,000 machine identities with almost no visibility into who created them, what they access, or how they're being misused. Entro solves this by discovering these identities across developer laptops and cloud environments, building comprehensive inventory with ownership lineage, permissions, and activity patterns. With AI agent adoption accelerating (roughly one AI agent per seven employees), this problem has become urgent. Alvas emphasizes the vendor perspective shift: understanding how CISOs prioritize spending - using industry reports like Verizon and IBM Data Breach reports to justify budget - proved invaluable to Entro's go-to-market strategy.
Non-human identities are credentials used by applications, services, and AI agents to authenticate against databases and resources. Entro's customer base shows an average of 144 non-human identities per human identity - a 1,000-person company has roughly 144,000 machine credentials to manage, yet most security teams have no visibility into which ones exist, who created them, or how they're being misused.
He and co-founder Adam conducted 200+ one-to-one validation interviews with CISOs and security practitioners, asking whether they knew how many non-human identities they had, if they wanted that visibility, and why. About 80% confirmed the problem and indicated budget availability, which both validated the market and de-risked investor concerns.
Every AI agent that accesses data must authenticate using APIs backed by non-human identities. Since Entro already offers the leading non-human identity security platform, they can map which AI agents exist, which identities they use, what permissions they have, and flag abnormal behavior - making them naturally positioned to own both the non-human identity and AI agent security layers.
Send hundreds of one-to-one LinkedIn messages (not mass campaigns), leverage your existing network and referrals, attend events, and focus on conversations where people actually respond. Use early conversations to refine messaging before raising seed funding, when you still have time to iterate.
They prioritize based on industry reports like Verizon's Data Breach Index, IBM's Cyber Security Intelligence Index, and Gartner reports - identifying the most frequent attack vectors and matching them to available budget. Explaining your solution against documented threats in these reports makes budget justification much easier.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid, practitioner-grounded insights about non-human identity management and go-to-market strategy, including the 144:1 ratio metric, the validation interview process (200 interviews pre-launch), and specific frameworks around customer prioritization using industry reports. However, it relies heavily on repetition of core concepts and lacks density of novel claims per minute; significant portions are soft narrative filler.
for every human identity there's on average 144 non human identities, which is an insane number
we've done that validation for at least 200 different organizations and security practitioners
The core insight - that non-human identities are a blind spot for security teams - is original and grounded in the founder's lived CISO experience. However, much of the execution advice (validate before building, talk to customers, build an MVP early, use data-driven prioritization) recycles well-known startup playbook elements. The AI agent angle is timely but not deeply counterintuitive.
Unlike human identities, you literally don't know anything about them
we took that solution to a lot of different CISOs and security practitioners before even starting to code
Itzik Alvas is a strong, credible guest with direct founder experience and prior CISO tenure at scale (Microsoft Defender, Office 365, large healthcare company). He demonstrates domain expertise, has lived the problem he's solving, and founded a company that's evidently gaining market traction. However, he is not a household name founder or serial entrepreneur at a unicorn scale, which prevents a higher score.
I was responsible for internal security of Microsoft Defender cloud, prior to that of Microsoft Office 365 Cloud. Prior to that was the chief information security officer for a large healthcare services company
I was breached a few times by non human identities which kind of led me to think a lot about the problem
The episode provides concrete data points (144:1 ratio, 1-in-7 AI agent adoption, 200 validation interviews, 6-month MVP launch window, Google Ads ROI metrics like $100 spend → $150 return) and references real companies (Microsoft, Palo Alto, CrowdStrike, ServiceNow). However, most examples are either aggregate metrics or high-level references; few granular case studies or named customer wins are provided, and quantitative rigor is moderate.
for every human identity there's on average 144 non human identities
every seventh employee on average is adopting AI agents
The host asks solid, open-ended questions and elicits useful founder advice, but rarely pushes back, challenges claims, or digs into contradictions. Questions are mostly affirmatory and narrative-guiding rather than inquisitive; there's limited follow-up skepticism, no pushback on competitive positioning claims, and minimal probing into customer acquisition costs or churn. The conversation flows naturally but lacks intellectual friction.
I'm curious, first of all, how does it feel now?
What do you think? You know, that people who perhaps haven't sat on the other side of the fence don't know about
Computed from the transcript - who did the talking, and the words that came up most.
Most cybersecurity founders build for a problem they've studied. Itzik Alvas built for one that had already beaten him. As former CISO of a large healthcare services company and responsible for the formal security of Microsoft Defender Cloud and Office 365, Itzik had been on the receiving end of non-human identity breaches before most of the industry had a name for them. When he left to co-found Entro with his partner, Adam, he wasn't guessing at the problem. He had lived it. Non-human identities, which are the credentials applications use to authenticate against resources, databases, and infrastructure, are now the second most frequent attack vector in cybersecurity. For every human identity inside a company, there are, on average, 144 non-human identities. In a company of 1,000 people, that's 144,000 credentials most security teams cannot see, cannot track, and cannot manage. Entro was built to change that.
Transcribed and scored by The B2B Podcast Index.
Speaker A: But at least from our customer base, we're saying that for every human identity there's on average 144 non human identities, which is an insane number like to manage that amount of. So, you know, take a pretty small company of 1000 employees, they will have on average 144,000 non human identities. How can you even start to manage or protect or secure them?
Speaker B: Welcome to Cult Products, a podcast by Yaya Digital. I'm your host, Phil Keeney Bolland and on this show we sit down with the founders and leaders shaping the next wave of cyber security innovation. You'll hear the stories behind how they found their first customers, defined what made them different, and built products that earned a loyal following in one of the toughest markets on earth. Let's dive in. Hey Itik, and welcome to the show. Thanks for joining us away from a freezing cold Boston. Great to have you on Cult Products.
Speaker A: Thanks for having me Phil.
Speaker B: We could just jump in. I'd love to hear a little bit about your story. So what was it that led you to found Entro?
Speaker A: So Entor is a non human identity and uh, AI agent security company just to frame non human identities. They are being used by applications in order to authenticate against uh, resources, application needs. So if an application needs to authenticate against a database, they will use non human identity to facilitate authentication. Before Entor, I was responsible for internal security of Microsoft Defender cloud, prior to that of Microsoft Office 365 Cloud. Prior to that was uh, the chief information security officer for a large healthcare services as a company. And um, I was breached a few times by non human identities which kind of led me to think a lot about the problem and to join forces with a friend of mine. He was working for Broadcom and Broadcom back then had an event around non human identities. So we talked a lot about that and tried to figure out what can we do. And once we thought we found a solution we actually left and started intro.
Speaker B: So this is super interesting. So you've actually have been a ciso, you've been experiencing all these problems and the whole motivation for you was really related to that experience, which is cool, gives you a huge leg up by thinking about how to solve these problems. I'm curious, first of all, how does it feel now? You've gone from being presumably approached by quite a lot of tech businesses and sold to being on the other side of the fence where you're now having to think about actually selling to other CISOs. Uh, how has that transition felt?
Speaker A: I never saw the go to market side at all. Like I never understood the force of marketing and sales and so forth. So it is a learning experience for sure. I was yes, always on the security practitioner side, always on the customer side, always being sold to. And it was weird at first but it's great because now you are able to see both sides of the coin and to understand kind of the full picture. Not even a has always been a huge issue. It's uh, today the second most frequent attack vector out there. So um, maybe we're in an easier market. So for us to generate leads, ah, or to. I wouldn't say easy. It's never easy, but maybe easier. I think also my background and my partner Adam, the co founder and CTO background in security really, really helped.
Speaker B: Really? What do you think? You know, that people who perhaps haven't sat on the other side of the fence don't know about how to build trust and connect with that uh, audience.
Speaker A: When you're on the vendor side and you're trying to sell, you want to kind of understand the buyer side. You want to understand how decisions are being made and who's in the committee and how do you prioritize stuff and so forth. And I've been there, I've done that for years. So the way that I used to prioritize when I was responsible for security, the way that I used to for budget and so forth is basically taking the leading reports in the market, the leading reports at least in CyberSecurity Market I, IBM, Cosmos of Data Breach, the Verizon report and Gartner and then see what's the most frequent attacks out there. So if phishing is number one. Okay. Do I have something for phishing? I do. Great. Non, ah, human identities. It's number two. A agent. It's number three. Do I have anything for them? No. Okay. That's my next project. And it's pretty easy to explain that. It's pretty easy to ask for budget from either the CEO or the board or whatever because those are industry reports. Most of the attacks are going down that route and we have nothing or uh, what we have is sufficient. And even understanding that part is super, super critical. Right. Because you're helping your customers to explain why they need your solution. Because they can get it. They can get it. On the technical side they are seeing the problem. But sometimes proving the budget and explaining it to non technical folks can be a challenge and I think that's really, really helping.
Speaker B: It's interesting. If I was going to sort of just summarize what you've just said there it would be. Life is a lot easier if you pick a problem to solve. That is a really big problem that people are actually feeling the pain of for sure. If that demand is already there and people are already looking for ways to part with some of their budget to solve it, it does make things easier. And non human identity is something we're certainly having a lot of conversations about. I think obviously with the rise of agents and all of the kind of innovation that's been happening recently, it's a big topic of conversation. And you know, identity in general, I know, is one of the things where CSAs are kind of feeling the most pain for sure. What is it about what you're doing at Entro that sets you apart from all the other people that are trying to address those problems?
Speaker A: Yeah, no, I agree. Identity is definitely the new frontier and you're seeing like the market reacting to it with the Palo Alto acquisition of CyberArk and CrowdStrike acquisition and ServiceNow acquisition and billions are being deployed to solve the problem. And yeah, back then we had firewalls or network as a boundary and now it's identity. You know, everything is in the cloud, everything is accessible. The identity is what let you in. And let me share one statistic with you. At least from our customer base and we have enough, uh, maybe not enough, we always want more. But at least from our customer base we're saying that for every human identity there's on average 144 non human identities, which is an insane number like to manage that amount of. So you know, take a pretty small company of 1000 employees, they will have on average 144,000 non human identities. How can you even start to manage or protect or secure them Nowadays for AI agent, every seventh employee on average is adopting AI agents and have AI agents. And I'm not saying that take the number of employees and divide it by seven and that's the number of AI agents, but every 70 employees has at least one AI agent. So it is fastly growing for sure. And it is the new frontier. That's how you're accessing data. So yes, identity is definitely, definitely, definitely top of mind. And what we're doing amazingly tanto, is we're able to. Let's take uh, one step back. The main problems with non human identities or agents is that unlike human identities, you literally don't know anything about them. So human identities are your employees, right? They represent your employees. You're hiring more people, you're creating more human identities and you know, everything about your employees, right? You know their name and maybe their SSN or id, how they live and what they're responsible to and so forth. You have nothing of that sort when it comes to identities being used by applications or AI agent or agentic identities. I uh, usually don't know who's creating them and where they are and how many you have. And if you find one, so non human identity, if you ever seen it, it's a long randomized string which means you don't even know if it's actually anonymous identity or just someone fell down on his keyboard like you have no idea. And even if you can validate it's a non human identity, like then what, who's the human owner, which application is using it to access what resource, what permissions they have, how it's being utilized, is it being misused. And all of those question agents as well, who created it, what permission for what, how it's being utilized, is it being misused. And so the main problem is security teams usually know nothing. All of those identities, they don't know how many they have, they don't know who created them, they lack a lot of context, uh, they don't know where they are and so forth. And I think that's what entro doing. Amazingly, we're able to discover those non human identities and AI agents everywhere. We're able to find them at the laptop of uh, a developer or up in the cloud. We're able to give a full inventory inventory, very comprehensive inventory that answers the question of how many AI agents you have, how many non human identities you have, where they are, how they are being utilized. We're creating a lineage map of which application is using what non human identity to access what resource, a lot of vital information like with the human owner permissions activities and so forth. So now you have a full picture of all of your identities and we're connecting the dots so you can see all of the interconnectivity that human invoke that AI agent to use that non human identity to access that data within the environment. And then it was also someone from, I know North Korea tried to use it, so that's an abnormal behavior. So we paused that or disabled that and so forth. So we're granting amazing unparalleled visibility and then we're using that visibility in order to do management actions and security actions.
Speaker B: I'm curious in a space that is, there is a lot of competition, right? There's a lot of people out there trying to solve the same thing as you. How Much time do you spend kind of looking over your shoulder looking at what competition are doing, letting that kind of inform your product strategy versus you have your own vision, you know what makes you different and then you're following your own path.
Speaker A: I see all forms of feedback as a good feedback and maybe it's feedback from our customers and maybe it's feedback from our internal team and maybe it's something that we're seeing that uh, our competitors are doing all forms of feedback and every low, uh, learning is a good one. We were the first company to introduce non human identity solution. We are the first company to introduce the AI agent Identity Security 2. So usually it's our competitors learning from us and I'm super proud of that by the way too, what we're doing and that we're paving the way when seeing so many other companies following, following uh, our footsteps. But for me, you know, it's not about pride or anything else. If we're seeing somebody else solving something in the right way, competitor or non competitor, a uh, customer that is offering it to us or recommending it or whatever it's going to be and whatever it's going to be, we have our own internal process to evaluate those kinds of stuff. And if it makes sense, it makes sense.
Speaker B: And do you feel like where you've ended up is where you expected you would get to when you first started the business or do you, you've learned so much along the way that you've ended up in a surprising place?
Speaker A: That's a good question. I think both. I expected it to be a huge space and a fast growing space. I know that I suffered from that. I know my peers when I was a CISO suffered from that. So I understood the solution is needed for sure and I expected it to grow and grow fast, but it's also surprising that it is growing that fast, you know, so it's always a surprise, always when you're doing something new. And I love changes by the way. I think changes are great, but definitely in the startup world like every day is another change and it's surprising.
Speaker B: And speaking of changes, Agentix obviously been a massive disruptor in this space. How do you feel? Because it's such a seismic shift and it happens so, so quickly when you're trying to kind of plot a course for your business and things are changing so rapidly. How do you keep up with that?
Speaker A: I think we're at the eye of the storm. I think we're entre is perfectly, perfectly positioned to handle AI agents and the security of AI agents. So for us it was definitely a gift. I'll explain it shortly. AI agents. The only AI agents that actually matter to security are uh, AI agents that have any sort of data access. So if you have AI agent that can communicate with your calendar, the security cares about it, right? And if you have an AI agent that is able to communicate with something else within the organization, read files or whatever, then security cares about it. In order for AI agent to gain any sort of data Access, they're using APIs, right? So if you have an AI agent that is managing your calendar, is going to use API to connect to that calendar and is going to authenticate with that API using a non human identity, even if you're doing like human delegation, it will result in a non human identity in the background. Auth token, that's the type of non human identity. So for us, the only way that uh, AI agents are actually able to communicate with each other or with any sort of data is by using non human identities. And we already have the best non human identity security platform out there. So it was kind of easy for us to explain to the AI agent too and connect the dots and say, okay, those are all of your AI agents, those are the non human identities that are accessing, those are the permissions, those are the activities, and therefore we're able to secure them too. Um, and it's also increasing the number, definitely increasing the number of non human identities out there. So for us it was truly a gift. We're perfectly, perfectly positioned over there in the market to control that market. And it's yet another fast growing market that we're uh, extremely good at and extremely well positioned at.
Speaker B: So you're very much in the right place at the right time, which is amazing. Uh, I guess how much of that is by luck and how much of that is by design. We started off talking about picking a problem space that feels big and important and super critical. Did you envisage it being just as high up the agenda, uh, as it ultimately has been, or has that been a pleasant surprise?
Speaker A: I thought it's going to be very high in the agenda and also like, it's not set up luck. So when Adam and me started ento and we thought about, we understood the problem very, very well and we thought about different solutions to that problem. And then we took that solution before even, you know, starting to code anything, we took that solution to a lot of, uh, different CISOs and security practitioners and we asked them, we were like, okay, that's the problem. Do you have it do you know how many non human identities you have? He said no, do you want to know? He said yes. Why do you want to know? Because those are identities that can access my infrastructure. And I'm like, yeah, so that's the solution we're offering. What, uh, do you think about it? And we've done that validation for at least 200 different organizations and security practitioners, most of them are CISOs and so forth. So we've definitely validated there's a huge problem out there. So that wasn't surprising. What is surprising is the AI agent and the wave it created and how much it's relevant to the non human identity. So that was definitely a pleasant surprise.
Speaker B: 200, uh, validation interviews before you hit
Speaker A: any, any code, even write one line of code.
Speaker B: That's amazing. I mean that is exactly what we would advocate people do to try and not just validate, but also shape the proposition. Can you tell me a little bit about how did you actually do that? How did you get in touch with people? How did you run those sessions? What did you do with the information? What did that whole process look like?
Speaker A: So there are a few things you would like to get out of the call. Ah, first of all, you would like to validate the problem. Maybe it's not even a problem, maybe why offering a solution if it's the sixth problem of them or the seventh, and they will never get to it, because if it's number seven, then you're gonna never do something with it. There's always gonna be a number two, a number one that will take all of the place in the sun. So first of all, you wanna understand if it's truly a problem, that's number one. And there are a lot of different ways to do that. It's not only asking if it's a problem, but it's asking, okay, so what do we do? How to solve it today? What have you tried and kind of understand how much is currently deployed in trying to solve it and then how difficult it is to solve it. So if he has teams that are working in order to solve that, like that's a pain, but right, uh, he's already investing a lot of money and time. So you want to validate the problem and then you want to validate the solution. So now you're offering a solution and the solution should click and click fast. And I think the best validation and that really helped us to get to that number is trying, uh, or asking, do you know anybody else with that problem? Do you know anybody else that would like to have that conversation too. If he's like, yeah, you know, I spoke about that recently or two months ago or whatever, and I do think there's maybe another person. Let me connect you to him. And he's connecting it to him. That means that we're probably like, he cares enough, that guy that you're speaking with, or lady. And then he thinks another person will care enough about that too. We had a lot of that. We had a lot of people referring us to other people. We had our own network that we utilize and we also had a lot of outreach. We basically sent over LinkedIn. We were like, hey, we think we have an amazing solution for that problem. And that's also kind of a validation. If people are like, okay, let's talk, then that's also a validation. You know, they are giving you their time under the premise that you found the solution and you're not even telling them the solution because it's too much for a message. That's what we've done.
Speaker B: That's super valuable advice. I think, about the referral thing. I think if you've worked hard to get in front of one person, that person does probably have people in their network who would also be interesting to speak to. And every opportunity to do that is great. I think that is a super strong takeaway for anybody listening to this. I chatted to somebody the other day and they said, effectively, how do we kind of get started with building out all that network and all that kind of stuff? And on the LinkedIn point, I said, that is a way of doing it. Use your existing network, Use the things that are closest in proximity to you, but expect to hear a lot of no's and expect to hear a lot of nothing as well.
Speaker A: It is what it is.
Speaker B: How did you find that experience?
Speaker A: I get it that a lot of people are not reading it or just see someone they don't know and they're not even reading, uh, the fourth word. I didn't read too much into that. If they are not responding, if they are responding, then you need to read into it. So if most of them would tell us no, it's not a problem for me. I wouldn't even take 20 minutes to talk about that again. That's good. That's a validation that you're working on the wrong stuff and you should probably move. I wouldn't say no shows, but people that are not responding, ghosting, whatever you're going to call it, you can ignore them, take them out of the equation. Uh, but the people who are responding, then you need to read what they are responding and if they are giving you the time of day.
Speaker B: Did you do this as a mass campaign or did you do one to one messages to people?
Speaker A: Mostly one to one messages.
Speaker B: One to one messages. And how many are we talking here to get to those 200?
Speaker A: So again a lot was from our network and by referrals. But um, I don't know, you know, we went to also events and talked about it in events and like just walking the floor. And of course I'm not specifying everything but we sent hundreds for sure.
Speaker B: It's a numbers game sometimes I think but hundreds of one to one messages. But it's a big undertaking. But as far as I'm aware there's not really a way around it.
Speaker A: Correct, but you also wanna like you're very early on. You also wanna find the messaging, try to understand what message is being picked up, why, what should they change. And you have time because you haven't took the seed funding yet. And that's your time to loan because once you're taking money off to the races, you know, you now need to deliver and deliver fast. That's a good segue.
Speaker B: You've validated the idea at this point. You've gone out to move to 200 people. This is definitely a problem. You know it's a problem from your experience anyway, you validated the solution. That must have helped a lot with securing funding.
Speaker A: I agree that helps uh, with securing funding. That's a true statement for sure. I think you know when you're trying to raise money wherever you are, you can be a late stage company, a very early stage company wherever you are. The um, the investor want to de risk itself. Right? That's what he's trying to do. He would like to de risk his investment. And there are a lot of ways to de risk the investment but definitely a huge one is we talked with 200 people, out of them 80% said ah, they will buy that and they have budget for that and so forth. And you can reach out to anybody from that list or I can maybe make the connection. It's a great way to de risk your investors. Definitely when you're entering a new space because we offer something new, it's not like next gen firewall and you know, you can still budget. We needed to create that budget and definitely there's a lot of risks attached to it and I agree that's a great way to risk it.
Speaker B: So how did you actually find it once you pivoted towards sales? Did you find that you converted a lot of those initial 200 people. Tell me about the early stages.
Speaker A: Those were definitely also our four star, uh, customers for sure. We kept in touch with a lot of them and we were like, okay, some of them also take two calls with our visas because they wanted to talk with them to understand the pain point too and so forth. But so they help us uh, secure the funding as well. But uh, after that, you know, we kept in touch and we were like, okay, we're building it. We're still in stealth, but we have something, do you want to try it? And then you have design partners and then they are paying customers and so forth. So yes, I think leaning on that validation is totally strong for sure.
Speaker B: I think what you've done is amazing because it's customer centric, it's all about learning, it's all about validating, de risking, all that kind of stuff and then ultimately really helps with that initial traction build as well. And I guess people feel like they've come along the journey with you by the time there's actually a product to buy, they feel like they've been listened to and had a hand in shaping it and that you've really kind of must understand the problem. That's the benefit to them really. And you've obviously been on the other side of this as well as, as a ciso. If you invest your time in vendors and startups and new ideas, I guess the incentive is you ultimately get a product that is much better suited to what you actually need. Right.
Speaker A: The biggest amount of eyes looking at what you're building, it's costing so much money. And I think that's something you need to emphasize. You need to, when you're talking with your customers and you're like, please tell me the truth because I'm deploying millions into that. And if you had millions, what would to deploy, um, in that problem, would you spend it on that feature or that feature that's costing 400k? Is it worth it? And if it says yes, then why? And if it says no, then why? And I think really explaining to them that it's not because everybody always going to look at uh, the button and will say, I wish that button will also do that. Fine, but try to explain the choices too.
Speaker B: You're painting a picture of very smooth sailing. You know, I think you've chosen a big problem. Well, I would be surprised, uh, if you were the only startup founder in the world who had just had totally smooth sailing. I guess, uh, if you think about looking back over the experience that you've had. Are there any things that if you had the luxury of a time machine and you could go back and talk to yourself at the start of the journey, what would you say? This is my advice. These are things that you should watch out for. This is how to deal with some of the challenges that are coming up.
Speaker A: That's too much. I think about maybe the top one, but that's definitely too much. You know, when I was a first time manager or when I managed the UM teams for the um, fifth time, that was very, very different. Right. So the same goes like first time founder or first time CEO or first time sales. Second time will definitely improve because I have a lot of learnings and there's many, many, many learnings. I think the overall that I would emphasize more is maybe delivering stuff even sooner than we have and we delivered stuff very, very soon. But even, even sooner, like going back to the point of you want to get as many eyes on what you're doing and what you're building. And I know even if you're buying and you whatever shirt you want to probably get everybody's feedback, it's not me, I'll buy it online and that's it. Feedback are good and if you can deliver stuff sooner, even if it's broken, then they will give you the feedback of what's broken. And if it's 10 stuff, then fine, which one matters the most? And even deliver stuff sooner than we've done and we've done it very, very soon. So it took us six months between the time that we raised our seed round and hired the first um, software engineer until we launched the first product. And that was six months is very fast, but still even faster. As much feedback as you can because you need to move fast.
Speaker B: When you say move fast, what are the specifics that we talk about? How would you have changed your process to get faster? Because I'm assuming at the time it probably felt fast. What is it, with hindsight that you think you might have done differently?
Speaker A: Of course you have your roadmap, right? Of course you have your roadmap and of course you're validating that roadmap and you're asking your customers and other people too and so forth if that roadmap M makes sense and why it makes sense and stuff like that. But nothing beats delivery, Nothing beats it's version zero, it's not even alpha. But I just wanted you to see it, play around with it and tell me what do you think? Um, and it can be totally broken, but you're gonna get a great feedback. If you're gonna do it like that and not wait until the beta release and so forth, even if you discuss that with him, even if you show them screens and wireframes, nothing beats experience. If you can deliver stuff in a, uh, more granular way, do it. Always do it.
Speaker B: Interesting. I don't want to paraphrase what you're saying, but what that sounds to me is not that you would necessarily build faster, but just that you would get feedback earlier in a, uh, less finished way.
Speaker A: Yes, I would release it faster. Even if it's the ugliest thing you ever saw. Like make that, um, just the expectation tell, hey, you know, it's again, it's not even, it's not even alpha, it's not alpha, it's not beta, it's not nothing. But that's what we're building. Um, you can kind of get the sense of where we're going. It's going to be beautiful, it's going to be seamless. Tell me what you think if you
Speaker B: had done that, what do you think the impact would have been?
Speaker A: So I think we've done that, but I, uh, think if you can do it better or if you can do more of that, then it means less time to deliver stuff that actually people want. It's going to shorten the time to get the right solution in place.
Speaker B: What I really love about everything that you've said is you've really put the actual customer at the center of everything. You know, it's all very focused on fine tuning what it is that you're doing around things that they actually need. And I wonder if obviously that's a great methodology and uh, what should be part of everyone's playbook. But I wonder if your experience of actually sitting on the other side of this and being a CISO has maybe colored that a little bit so that you know, your maybe able to empathize a bit more with those people that you're actually selling to naturally. And then think about this from the perspective of what would you want? What would you have expected from a great product? How sort of true does that feel to you?
Speaker A: I agree with that. And I think it's uh, one of our most powerful things about Entor that we've been there. Both me, uh, my CO founder, our VP of product, our uh, VP of R& D and of other managers in the company have been on the um, customer side, security practitioner side. And we understand them and we understand how they're thinking and their process and we can relate to them. And it's very, very helpful. You know, let me give you an example. Let's say you want to open a restaurant. You will probably open a restaurant at your hometown or, you know, where you know the flavors and know what people think. And you're not going to go and do that in China, right? Because you're probably going to fail. You don't know the audience. You don't know what they like. You don't know nothing. Probably. Maybe you've been there a lot of times, but. But you're getting the sense, right? Definitely, if you know your customer base and you understand them, and definitely if you're part of them, then Stuffer is here.
Speaker B: Tell me a little bit about, you know, looking ahead. I think we talked a bit about the journey to this point so far. Uh, when you think about broadening out that customer base and attracting more people, what do you think are the channels that are most likely to actually give you return on investment, get you new customers? Where are you focusing?
Speaker A: Our digital is working amazingly well. Amazingly, amazingly well. Um, for us, it's digital, but it's everything else, too. It's SDR and it's events and it's pretty much everything. I think digital is probably the best way to go, not interface. People are searching for the problem. I intend. And I think it's, um, it's also like a machine, right, because you know that you're paying whatever 100 bucks to do Google Ads, but down the funnel, you will get 150 bucks for every 100 bucks, you know, because of. You can convert customers like that. So it's kind of an easy process or machine to understand. And if you're able to build it, then you basically have a machine of money, right? You're. You're deploying. You're deploying 10,000 bucks in Google Ads, and you're getting a customer that's worth 100,000 bucks. So building those machines are super critical for any business.
Speaker B: I always like to think about those kind of funnels as actually building a product, and it can take a little bit of time to design it and get the different conversion rates going and all the metrics and all that stuff ticking in the right direction. But then once you've got it, you've actually got an asset that can power your business. Where I, I think I often sort of challenge people is you don't need to do a million and one different things all the time. And actually, you know, you spend so much time building one thing that's really, really good Put it out there. All you're thinking about is the time period, this is this month's thing. And then next month is another thing. As opposed to the actual level of kind of market penetration. Like how many people have actually experienced this thing? If it's a video, how many have watched it, if it's a, uh, download, how many have downloaded it? Then you get caught in this kind of washing machine of, well, now I need to create a new thing and a new thing, a new thing. But you never fully realize the value of the asset that you've created. And I think where I'm seeing, you know, really smart moves in terms of marketing and lead generation is where is where people are actually thinking about it. As we're building a machine here, this is going to be optimized as much as possible. And then we need to be able to continuously improve it and run it and build out all of those things.
Speaker A: Yeah, I agree. And you can deliver something new, that's fine. But continue to use the old machine or the current machine until the new one is taking over. Even we're all over 20 year old. So we remember Facebook changing from like a dashboard with games, farm stuff and so forth to the current Facebook. And that took them what, like five years, years to do. They delivered something new, but they relied on the current one until they shaped enough the new one. Right. So yeah, I fully, I fully, fully, fully agree. What was the name of it? Uh, farmville maybe.
Speaker B: Farmville.
Speaker A: Yeah, like entire Facebook was around farmville back then, but they changed it and they refined the new UI to what it is now. And now finally, like after five years, finally it took over. Uh, the metrics were better.
Speaker B: Uh, I think that was before farmville which was when it first started. Uh, and it kind of hit my, hit my university and it was just writing on people's walls and stuff. And then there was after farmville which was the point where I was like, I can't use this platform anymore. I'm sick of people sending me sheep and things. This is crazy. And then there was like post farmville where it just became like my mum sharing fake news and all the stuff that kind of comes with that.
Speaker A: So if Facebook can take five years in order to refine and shape enough the product to where it is today until they are making the switch, then everybody can write.
Speaker B: Yeah, we're sort of getting, uh, towards time. There's a couple of things that I just to really ask you about. The first is just for you and for enter and for the future, what are the things that you're really excited about, looking ahead.
Speaker A: I'm excited basically about anything, anything and everything in entro. Uh, I really love Intro. I really love the team, I really love what we've built. I really love the product, I really love the excitement that we're getting from our customers and I'm truly excited about uh, the AI agents. So we are seeing it growing. When we released our first AI agent solution, I think it was like one to 40 something people in the organization that adopted AI. Fast forward like what, nine months? It's one to seven. Let's wait for another nine months, probably almost everybody. And then we're going to start seeing um, multipliers and even faster AI is running faster than other technologies adoption that we've seen before, so probably even faster. So I'm super excited about that. I'm super excited that we're in the right place in the market and we have the right technology to control that. And yeah, you know, um, I'm pretty much excited about everything in Intro.
Speaker B: That's great. What is the, you're a relatively experienced founder now compared to lots of people who are setting up on this journey. What is the advice you would give to those people who are ah, just a little bit behind you in the journey? What do you think? Um, the most critical things are?
Speaker A: Ah, I uh, would give that to anybody in any scenario. Not only founder. If you're embarking on a journey that is a new one for you if you never experienced that and that can be your changing jobs. Uh, you want to be a restaurant owner in China, right? Like we spoke about earlier or whatever. If you're going to do something that is new to you, reach out to somebody that already done that, right? And uh, reach out to several of them and ask them, ask them m everything you want to know and um, and try to get a sense you're not going to of course get the full experience. But find those people that have been there, done that and ask for advice. I can give them mine, which is probably if you're starting lean on validation as much as you can. But the true advice is find yourself some friends or people that are able. And our industry is a great industry by the way. Everybody's willing to speak with everybody, everybody's willing to help everybody. So reach out to other founders, um, and build your founder network so you can, when you're gonna challenges, you can reach out and be like, hey, I got that. Have you seen it before? If so, what have you done? Find those few folks.
Speaker B: I think one of the things that as an industry, it is mass collegiate, which is really cool. Finding people who are just a bit ahead of you, I think is really great advice because realistically, what you can learn from the CEO of Palo Alto or something like that is going to be very different because it's going to be so far removed from the reality of what you're doing right now. So there's. Sometimes the big names sound, um, good on paper, but the people who are right in the thick of it are really interesting mentors. Isik, it's been a real pleasure to chat to you today. Thank you so much for your time. So, obviously people are interested in Entro. Head to the website. Is there anything else? How can people reach out to you if they want some advice? What else would you like to promote?
Speaker A: I'm available, uh, on LinkedIn. You can definitely send me a message over there via Entro website. Entro Security. I'm available, like, if somebody wants to talk with me or someone that didn't collect, that's easy enough to do.
Speaker B: Nice. Well, thanks so much. Stay safe in all the snowstorms and things that are hitting the east coast in a minute. It's been great having you on the show. Thank you.
Speaker A: Thank you for having me.
Speaker B: Phil Cot Products is brought to you by Yaya, helping cybersecurity companies define who they're for, what they do, and how they're different. To learn more, visit Yaya Co. And don't forget to search for cult products in Apple podcasts, Spotify or wherever you listen. Follow the show so you never miss an episode. On behalf of the team at Yaya, thanks for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.