The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Cyber Security District
Cyber Security District artwork

From Ethical Hacker to Serial Founder | Francisco Nina Rente | Cyber Security District Podcast

Cyber Security District · 2026-06-16 · 55 min

0:00--:--

Key moments - from our scoring

Substance score

48 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber13 / 20
Specificity & Evidence10 / 20
Conversational Craft9 / 20

Francisco Ninarente's career trajectory illustrates the evolution of the cybersecurity industry itself, beginning with computer security in the early 2000s through information security and cybersecurity to today's cyber resilience focus. Starting at age 12-13 with his father's computer, he built Certipean (2005-2010), Portugal's first non-academic incident response and penetration testing team, then scaled Dognettis MSSP across 22 countries before joining Proscur in 2017, where he eventually became CTO of the cyber security division managing global operations. His current venture, Art Resilia (founded 2021), repositions the market around resilience rather than detection - balancing offensive and defensive security - and operates as a 50-person MSSP serving four countries with plans to establish Benelux as its European expansion hub. Throughout his career, Ninarente emphasizes trust-based security education over fear-based messaging, having appeared on Portuguese national television at 22 explaining digital threats, and continues advising through EC Council roles and The Rock, Portugal's only cybersecurity incubator.

Key takeaways

  • →Focus and discipline in early-stage ventures matter more than chasing every opportunity - mixing products and services, or pursuing tangential ideas, dilutes execution and requires fundamentally different skill sets and team structures.
  • →Building trust through demonstrated competence (offering free audits and awareness campaigns) proved more effective for market entry and international expansion than traditional sales approaches, especially when security was perceived as 'black magic' in the early 2000s.
  • →The transition from technical founder to CEO requires deliberately building bridges between the technical and business worlds - learning legal, financial, and contractual skills while maintaining hands-on technical involvement prevents disconnection from core expertise.
  • →Timing market shifts toward emerging paradigms (cyber resilience replacing cybersecurity focus) requires continuous market analysis and positioning before the consensus shifts, allowing first-mover advantage even in mature markets.
  • →Sovereignty and corporate door-closures within large groups can create entrepreneurial opportunities for independent MSSPs, as customers seek alternatives to consolidated mega-vendors for compliance and operational flexibility reasons.

Guests

Francisco Ninarente

Topics in this episode

Incident responsePenetration testingCyber resilienceCertipeanDognettisProscurArt ResiliaMSSP (Managed Security Service Provider)Digital forensicsEC Council

Questions this episode answers

How did Francisco Ninarente transition from ethical hacker to running a profitable cybersecurity business?

He started with free penetration testing for a friend's e-shop in exchange for hardware parts while underage, then formalized this into Certipean (2005-2010), a non-academic incident response team supporting startups through the Coimbra business incubator, before scaling into Dognettis MSSP across 22 countries over five years.

What is Art Resilia and why did Francisco start it after leaving Proscur?

Art Resilia is a cyber resilience MSSP founded in 2021 based on the belief that the security market was shifting from threat detection and mitigation toward resilience - combining offensive and defensive security to help organizations anticipate attacks and recover faster, positioning the company ahead of industry consensus from organizations like the World Economic Forum.

What were the biggest mistakes Francisco made scaling his first companies?

Attempting to chase every business opportunity rather than maintaining focus, and mixing product development with service delivery, which require completely different management approaches, skill sets, and team structures despite both seeming valuable in early growth phases.

How did Francisco build international expansion from Portugal to 22 countries with Dognettis?

By being present in communities and at industry events, speaking about security beyond security-specific conferences, and building trust through awareness projects (like scanning Portuguese IP space and releasing anonymized vulnerability statistics to national media), which generated traction and opened doors in new markets.

Why is balancing technical work with CEO responsibilities important to Francisco?

He believes bridging the technical and business worlds helps understand both perspectives on the same problems, and he made it a requirement to avoid completely leaving the technical side despite management consuming most of his time, a philosophy he maintains across his current partnerships.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode is a 55-minute career biography with only a handful of actionable practitioner insights buried in biographical meandering and small-talk filler. Useful observations on trust-based security selling, product-vs-service traps, and culture-first hiring are present but arrive slowly and without depth.

there are two ways of selling security. By fear and by trust. So I don't like the first one because a lot of reasons but mainly because it's not ethical but also because it's a matter of someone come and put it more fear on top of what you said and you will lose the connection
it's very tough to mix product and services. Okay. In Dognettis we did that mistake. We had a um, very strong capacity in terms of service delivering and we were always trying to put products on

Originality

7 / 20

Almost all the business lessons (focus early, people matter most, trust over fear) are standard founder-circuit wisdom. The 20-year-old analogy comparing web-app pen testing adoption to AI adoption is mildly interesting, but no genuinely contrarian or first-principles argument is made throughout.

I remember that in the early 2000s, uh, a very nice company called Net Canvas, they put it in the market, the first tool to automate pen testing...people were oh, this will change everything. I will lose my job...that didn't happen and it will not happen with Gen AI either
20 years ago there were two types of pen testers. The senior ones...and the youngest ones that were starting to testing web applications, that new thing...it's basically the same that is happening now

Guest Caliber

13 / 20

Francisco is a genuine practitioner who built and sold a real MSSP, rose to CTO of a $5B group's cyber division, and is now on his third venture - not a career podcast guest. However, the current business is 50 people and regionally focused, limiting the scale of lessons on offer.

Proscurities a worldwide leader in terms of security. They have a uh revenue around 5 billion
we were 350 people more or less around the world um operating for SOCs, um mainly MSSP but also doing auditing consultancy

Specificity & Evidence

10 / 20

There are some concrete anchors - Prosegur's ~$5B revenue, 350-person division, 22 countries, 2007 Portuguese IP-space scans, Net Canvas named - but many claims stay vague ('a few countries in Africa,' 'top three banks in the world') and numbers are rarely accompanied by outcomes or timelines that would make them actionable.

we were doing this sort of scannings to, to all the, the um, Portuguese IP space...gather some, some intel about how vulnerable the, the Portuguese Internet was. And then we released this anonymized statistics
we were the first of seven companies uh that uh were part of the cybersecurity division of Proscure

Conversational Craft

9 / 20

The host occasionally pushes back well (challenging the 'luck' framing, asking for elaboration on meritocracy) but frequently asks long leading questions that contain the answer, and critical threads - like the actual mechanics of internationalization or the confidentiality message - are left almost entirely unexplored.

I don't buy into it. Okay. Right. You have to be lucky for 20 years straight. Then, then you, you need to do some very good things
I feel throughout your career you've been sort of a trendsetter, uh, always a bit ahead of the curve, kind of a visionary. That is, is a ah, big strength

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B78%
  • Speaker A22%

Most-used words

security38started26important23knowledge22first21world18different17market17part15team14speaking13nice13resilience12back12journey12together12

Episode notes

What does it take to build a cybersecurity company not once, but twice from the ground up? In this episode of Cyber Security District, we sit down with Francisco Nina Rente, one of Portugal's most accomplished cybersecurity entrepreneurs. Francisco started his journey as a teenager tinkering with computers and quickly found his way into ethical hacking and open-source security communities. That curiosity became a career, which then led to a company. His first venture grew from a university incubator into a 250-person operation delivering services across 22 countries, before being acquired by a global security group. After years scaling that business from the inside and taking on roles as country manager, CTO and board member, Francisco stepped away to build again. This time, the mission is clearer: help organisations stop just detecting threats and start truly recovering from them. Art Resilia was born out of a conviction that the market was shifting from cybersecurity to cyber resilience, and Francisco positioned the company right at the centre of that shift.

Full transcript

55 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to Cybersecurity District, the podcast where we interview the most inspiring minds in the cybersecurity industry. Get ready to meet our next guest in the District. Today we're speaking with Francisco Ninarente, one of Portugal's most successful cybersecurity entrepreneurs. Starting his career as an ethical hacker and security researcher, Francisco has successfully scaled different cybersecurity businesses. Today he's the CEO and founder of Art Resilia, a fast growing cyber resilience firm rapidly expanding across Europe. He also continues to give back to the community through various advisory roles, including the EC Council. Francisco, welcome to the show. How did your journey into cybersecurity begin?

Speaker B: So first and foremost, thank you very much for having me here. It's a pleasure. So we actually started very, very early. Um, I started to get this passion around computers. Um, back then around 12, 13 years old, the only computer in the house was from my father. So the main purpose of that computer was for his own work. But uh, I also shared with my sister to have Internet access and so on. And it started there because I realized that, okay, so this kind of machine, uh, gives me access to knowledge but also will allow other people to have access to my own life. So security start to become important, uh, or relevant back then.

Speaker A: And was it also the example that a lot of good hackers have that they start with the school library?

Speaker B: Yeah, kind of, kind of. So um, yeah, I was part of some communities, um, one more related with security, others more related with like open source projects or whatever. Uh, but yes, yes it started in the usual way in the kind of the good and the ground, uh, where people openly share knowledge, experiences and build stuff together.

Speaker A: And it started probably very innocent and just fooling around with other boys and girls as a teenager. And at some point you really see, okay, this is uh, where I want to take my journey forward to. At some point it goes from ethical hacking, doing a bit of research actually to going into uh, a proper business valuation. Can you explain how you went into turning this into a business concept?

Speaker B: So we take a few years obviously. Uh, so even before went into, to university, a friend of mine that uh, was a owner of a small E shop, he put me this, this kind of challenge. Okay, so I don't know if my platform is secure enough. Um, so there is this kind of auditing people is calling penetration testing. And if you do that to me, I will pay you in hardware parts. I don't, you cannot have a wage, obviously you are uh, underage. So um, and I accept it. So that was Actually my first professional job. Let's, let's do that.

Speaker A: What type of hardware are we talking about? Like gadgets?

Speaker B: Yeah, no, no, like even parts to build a better computer, like a better cpu, more, more memory, hard uh drives, whatever. So, so later on I went to, to study computer science and in the second year um, I started to do uh, do some side jobs. So initially establishing and helping uh, um networking, um uh companies to, to deploy um routers and configure them and whatever. And then on my fourth year I challenge uh the business incubator of, of the city Coimbra where the city where I was studying to create uh a CSER team, uh incident response team to support the startups there. And I said okay, uh, there is this kind of idea of emergency team for the digital world. So if something happened, if you have an incident, probably an attack, we can help you out to identify what was the root cause and mitigate that and all that. So and they said okay, let's do that. So between 2005 and 2010 um, uh with two close friends which actually are uh still uh together uh in art Brasilia. So we created certipen this first incident response team non academic in Portugal and we started to deliver some services, some pen testing, digital forensics. Later on some consultancy about security architectures both on software side and network side. And it started there. So it was a kind of uh, an opportunity merge with the will of doing that uh in terms of professional

Speaker A: uh life and initially to just learn from that experience. So it was not like a value proposition. It was okay can we help the other startups in the ecosystem for free so that we can also learn and uh um become better at what we do. Is that correct?

Speaker B: Yes, yes it actually it was that, that the case and ingenuously we were thinking okay so this is, this will be the best way to, to to learn. But also we, we knew that security back then was kind of black magic so it was not easy to sell it to explain to someone that was outside of the scene. So we find this way of case doing. Okay, let us show our skills uh ah in the, in the um by helping you out and, and after that no strings attached, but after that if you want to go further we can speak about business. So everything started that and, and besides uh the that ecosystem around the business incubator we also uh did a few, a few uh, we call it dissemination projects. So we, we launched uh, uh projects to, to create awareness around security. For example between uh 2008 and 2010 we were doing this. No. 2007. Exactly. So we, we were doing this sort of scannings to, to all the, the um, Portuguese IP space, uh, or Internet space. Let's, let's go this way and gather some, some intel about how vulnerable the, the Portuguese Internet was. And then we released this anonymized statistics to people to understand if our Internet in Portugal was being correctly built and with security in mind and so on. That gave us a lot of traction. Media enjoy that. So it was very funny having 20 years or 22 years old and do some uh, interviews on the national television and so on and telling people okay, so the, there are bad people on the digital world, be aware. But not everything is bad. So digital world needs to, to be protected because the economy depends on it. So it was very, very very nice, nice journey uh, helping people and learning at the same time.

Speaker A: I feel you really were early on looking at uh, you personally so being, being still a young guy but also you call it black magic. So for other people talking about the incident response, this was probably a completely new concept. I feel throughout your career you've been sort of a trendsetter, uh, always a bit ahead of the curve, kind of a visionary. That is, is a ah, big strength but probably also difficult because it's a lot about education and awareness. How were you able to get on like national TV when you're 22 years old? Uh, did you scare people or what was your approach? I don't know.

Speaker B: I mean I usually see say that there are two ways of, of selling security. By fear and by trust. So I don't like the first one because a lot of reasons but mainly because it's not ethical but also because it's a matter of someone come and put it more fear on top of what you said and you will lose the connection. Right. So trust is always the way. So every time that we were doing those awareness uh projects uh, or even helping out people, we were trying to do by that approach building trust and telling them okay, so I will try to invade your infrastructure but don't, don't be afraid because we will not destroy anything. We are here just to give you the chance for you to know your vulnerabilities before a uh, bad guy comes and ah, breaks in. Right. So we tried to do our best and explain how, why security is very important on the digital world. Right. So it was like I said, a nice journey. We, I like to think that we were somehow successful on that. And later on with Dognettis we also started to do that in Ah, different countries. So in going a little bit ahead, uh, on the story, so after certificate, the CSER team, we founded Dognettis mssp and we were running for five years before joining uh, a big um, security group called Proscur. Uh, I will go that in a few minutes. But during these five years we managed to start to deliver services to 22 countries around the world. So, and we will always try to do both things in parallel, so business and contribute to the society itself by giving awareness and so on. So this, that uh, we started in Portugal, we did it in a few countries in Africa or even in England back then. Obviously England was a much, much mature market with a lot of players and so on, but still there was some space for us to contribute. So this was kind of our signature. Doing business but trying to contribute to the society at the same time.

Speaker A: Yeah, because it's a incredible journey that when you're 22 years old you get the fame. So you said we felt like successful boys. Uh, but then going in a few years of serving 22 countries, that's like a big step. What was sort of the tipping point that you felt, okay, now people want to talk to us, not only in Portugal, but across Europe, in Africa.

Speaker B: To be, to be honest, I think it was lucky, to be honest. What it was more about being in the, the right place at the right moment, you know, uh, so security was booming back then and not as much as now. Nowadays security is, is present all over. Right. But even then security started to be a concern in some sectors, special financial, but not only so and we were there, right? And people, we were being part of communities, being in events and so on. So even not security related events, it general events, but we were there speaking about security and so on. So that was like the trigger to open new uh, markets. It's kind of arrogant, uh, saying this in this way because was, I mean 22 countries, but very small business. Uh, anyway. Okay, so not the big multinational thing. Okay.

Speaker A: So yeah, no, but still you, you come from a strong security background. You really come from within the hacker community. So you know the skills of a security researcher, a pen tester, etc. But then you have to also learn new skills of becoming a business person.

Speaker B: Yeah.

Speaker A: So you have to deal with contracts and uh, waivers and in the legal documentation. How was that transition from security person to a business person as well?

Speaker B: Wasn't easy at all. So we were three founders, um, so and all of us, uh, were very geek person people. Right. So, and in the end of the day, I was the one that had to, to. To have the suit and the tie and to learn all that, you know, so, and, and it was quite difficult in the beginning. I mean it was a different uh, um, wording even when you were speaking with someone in the technical perspective is completely different as you know, on the business level. So learning all that learning the legal, the legal component, financial components of managing uh, a uh company, um, it was tough. But I have to admit that nowadays I really enjoy to do it. And I see that it's quite important to have, I mean in terms of skill set, it's quite important to, to build, I mean personal speaking, to build this bridge between the technical and the business world. It help us to understand better both sides of, of the same topic. Right. Um, so it was difficult, but it, it was impossible to not do it. So we did it basically.

Speaker A: But uh, your, Your co founders, they saw you most as the, the business guys, the CEO. So you became uh, the CEO.

Speaker B: You have to ask them. But I would say that was, that was like um, we, we kind of agree. We agree upon it. I mean we said okay. Uh, I said okay. I don't want to leave the technical side. Even nowadays I put a lot of effort on. Of or in not leave that part aside. Okay. So I, the major part of my day is related with management, but still I do uh, some, Some technical, um, some technical work. And that was the, the only requirement on my side. Let's put it this way. And they agreed and, and, and then we kind of find uh, our, Our own space. Right. Uh, each one of them, Sergio and Hugo, they have very particular personalities, different personalities and all three together. I think we complement each other. Um, and even. Okay. Nowadays only Sergio is, Is uh, one of the partners of Art Gasilia who is still with us, which is a very good thing for us. And we have Arthur, uh, Zila have two other um, uh, founders, uh, Andrea and Gonzal. But this, this atmosphere of, of uh, being open to complement others and make like a perfect balance in terms of the final puzzle. It's still there. So it still applies on Art gazillion the same way that applied in Dognettis or even in Certipean.

Speaker A: When we fast forward, you already said uh, in a couple of years we, we grow and we enter new uh, countries and you also become part of a bigger security vendor. Can you walk us through that process?

Speaker B: Yes. So it was very funny back then. We were very lucky. A lot of investors approached us. But um, probably and seeing now we were a little Bit naive. And the first contacts with those investors were purely financial. And we were saying okay it's important money it's important obviously. But we were kind of looking to a uh different approach and then Prosurge uh especially a person that was managing uh Proscur in Portugal. So Proscurities a worldwide leader in terms of security. They have a uh revenue around 5 billion doing. They started with with Catch Cash management then they went to man guarding electronic security and later on to cyber security. So and and and uh. Joao the the country manager approached us and he said okay we have this project on of building a 360 security offer because we believe that that risks and threads that sometimes started on the physical world can affect the digital world and the other way around. And that was like of music for our ears. You know it makes all the sense. It was a, a very, a very nice paradigm. Uh we saw space to contribute like technical speaking um with with other divisions of the the group. So we accepted and we went, we entered entered the group. We were the first of seven companies uh that uh were part of the cybersecurity division of Proscure. Some of them were just pure investments on product uh startups. The other ones were uh part of uh um uh like uh a uh merged uh uh Emerge Service provider merge from the acquisitions. Right. So in the end we were 350 people more or less around the world um operating for SOCs, um mainly MSSP but also doing auditing consultancy. And in that uh five years that we were inside of Pro School Group uh help us a lot to see. I mean the inside of a corporation it was a completely new world for us with good things and bad things obviously like everything in life. Um but we enjoyed and we also had access to different type of customers. For example before we were working with national banks or small banks and inside pros good we had access and we started to work with with the top three banks in the world saying or things like that. So huge corporations uh that we we we we never had the chance to work before. So how old were you at this age? So I need to do some math. So it was in 2017 that we joined the group. So I was around 32 33.

Speaker A: Yeah. And what, what was your responsibility then joining the new organization?

Speaker B: So in the beginning I was just managing Dognettis and I keep my own rule and CEO. So uh, when Dognet is um joined Proscur the Proscur already started uh internal team based out of Spain. Um so the first step was to try to, to put Dognettis and that internal team Pros Gursi Versigurida the the was the name back then working together and then each time we were uh acquiring uh new companies. Um we, we had the M and A process. Um so uh after that I had like a uh rule focus on. On non Spanish speaking countries because pro school started in, in Spain ah after that went worldwide. But so and in the, in the management level they you they like to split the markets in what is a uh Spanish speaking country and, and the non speaking country. So the next role I had was managing the non Spanish speaking countries. Uh after that uh after that I went as CTO of, of the the the the the cyber security division. So um, my responsibility was on the technical side of all the the countries that joined the division and helping to, to create synergies at the operational level and, and making the bridge to the sales side as well and so on. And that was actually my. The last role on the group.

Speaker A: And then what happened then, then you. I wanted to become a true entrepreneur again because you transition slowly from this young security uh researcher into starting your own thing. And then the team gets acquired and then within the bigger company you get more responsibilities, bigger clients. And then at some point something feels I need a change.

Speaker B: Yeah, no no, it was, I mean it was life happening. You know, um, people change, organization change. And the strategy proscur had was not the same uh that they presented to me in the beginning. So I respected that but I didn't fill the line with that. So I decided to step out and when I decided to do it I didn't have in mind. What do I uh, I mean I didn't decide it um right away what, what. What could be my next step. Okay. So I um, initially started to do uh, um a business incubated focus on. Focus on cyber security. Where where which I still contribute nowadays is the, is still the only um cyber security incubator in Portugal called the Rock. But a few months later um, some of my colleagues were saying okay, we are not, we are thinking on leaving um Cypher Cypher was the brand used to the old division on the last years. Um but we would like to work together again. So we started to speak and we said okay, let's try to do this again. Let's try a new journey. And Art Resilie came up based on this belief that the market was about to change. So uh, 2022, 2021, let's let's put it this way. We, we analyze the market and is. We said okay, the market will change again. So cyber security is, is the hot topic. But uh, and, and people know that is important to detect threads and to mitigate that. But uh, people is now realizing that is a matter of time, uh, to suffer an attack. So in the end of the day, what is, what will be important? It was from one end or in one end try to anticipate those attacks and be more prepared to defend it. And in the other end to be capable of recovering uh, uh, from that, uh, as fast as possible. And that has the name resilience, right? So we said okay, we don't have a sure, but probably the market will start to speak about cyber resilience sometime soon. And then we see big organizations like the World Economic Forum, the United nations, saying oh, the world needs to be more cyber resilient. It's important, and so on. And we said okay, that is our, our call. So we built Art Gazil around this. Okay. We, we take uh, we leverage upon of our, of our experience. We basically started when the market was speaking about computer security, right? And then information security and then cybersecurity and now cyber resilience. So Arthur Zille came upon this idea, uh, to build and to deliver resilience based on uh, a uh, balance of offensive and defensive security. And that is, it was the beginning of Arthur Zil, let's put it this way, uh, a, uh, group of friends with a common passion that looked into the market and said oh, maybe this is a nice opportunity.

Speaker A: Ah, nice that the resilience part was popping up elsewhere in the market. And that was uh, the clue and why the name Art Resilience.

Speaker B: So even the previous name, Dog Nedish, uh, it came um, or it's basically a merge of two Latin words, Dognitash and Aedish. Uh, aedish means temple and dognitas knowledge. So we wanted to be a temple of knowledge for our customers. Art Gasilia evolved in the same, uh, the name came up in the same perspective. So the art of resilience. We want to help uh, our customers to build resilience in the kind of artistic way. Let's put it this way.

Speaker A: Nice. I love it. Catchy. And uh, where are you standing now? With the company.

Speaker B: So we were once again very lucky. So uh, we um, started uh, our operation in late 2021. And during the first two years, um, we need to say this, we didn't did any sales operation at all. So we were lucky enough that the market was coming to us. Um, some of Them actually told me so me and my partners. So Francisco, it's, it's good to see you again on the entrepreneur side. So let's do things together. And I realized that obviously the corporate world has very good things, but also closed some doors, um, for a lot of reasons, namely sovereignty, which, which kind of important thing right now. So we, we end up to grow very fast, um, on the Portuguese scale. Let's put it this way. The first three, three years we were very focused on the Portuguese scale. We, we are now, um, MSSP with around 50 people. We are delivering, uh, services for four countries now. Um, and we decided, uh, like the same way we did it in Dognadish, we decided to approach more mature markets to hoping that we find more, uh, challenge customers. Uh, because in the end of the day, like I said, we are geek people. So we need, we need tough challenges to be happy. Right. So we decided to. In, uh, Doc Net is we decided to start this internationalization journey through the uk but after Brexit, it doesn't makes very much sense now. So we choose Benelux to try to do this, this uh, initial, uh, step of our internationalization for a lot of reasons. But first, it's a very mature market, especially Netherlands. Uh, secondly, um, everyone speaks English probably better than I do. So it was kind of easy for us. And third, it works nowadays as a bridge for the rest of Europe. So it makes sense for us. So we started, uh, in the end of the last year, um, our journey here. We are establishing a team here, um, and we hope that two or three years from now it will be, uh, our most important market.

Speaker A: Yeah, uh, it's an incredible journey. Again, I hear you say luck a couple times now.

Speaker B: Yeah, I have to admit it was. We have a lot.

Speaker A: I don't buy into it. Okay. Right. You have to be lucky for 20 years straight. Then, then you, you need to do some very good things. So I'm curious, maybe what, what, what, what are some of the lessons that you've learned now as an entrepreneur that, that you wish you knew when you started. So if other young, you say geeky or technical people want to start, what are some of the things that you had to learn the hard way these last 20 years? Want to share with them?

Speaker B: Oh, there are so many. But I would say, okay, so top three, first one. In the beginning, people think that, okay, I need to take all the chances I have. If there is a chance to do the deal, I will do it. That could be a mistake. Focus. It's very important. I Know that is tough because in the beginning any penny counts. Right. But uh, focus will somehow drive your. Your resilience over the journey. Right. And I made a lot of mistakes there. Okay. Um. Um. The whole team was like I said, geek. So if, if there is this idea of building a tool or the product, let's do it even if it is outside a little bit outside of our focus. So and that. That was uh. That was probably the first biggest uh lesson learned that we had. Um, the second one is it's very tough to mix product and services. Okay. In Dognettis we did that mistake. We had a um, very strong capacity in terms of service delivering and we were always trying to put products on. On the market. It, it kind. So it had some good things on it because the word products based on needs that we saw on the market back then. But in other end it's a completely different animal in terms of management and even the teams need different skill sets. So that, and that could make sense in the later stage when you are big and you have uh, a lot of people people and you can actually have kind of have more than one company inside that single company. Right. Different the management structures, even skill sets, but living together. But in the beginning that is a mistake. Okay. We need to choose product or service. So Artzelia was pure service.

Speaker A: Yeah. Nice.

Speaker B: So we are now developing some technology to leverage our services. But that is a different thing. First is it was not in the beginning. So we have five uh, years now. So uh, we are not in the beginnings of the beginning of the beginnings. But um. And also it was. Is not a full fledged product with the whole cycle and all that. We are building technology to leverage or to differentiate our services. That is one thing. And, and the last one, uh, we cannot forget that always the most important thing is uh, on. On the business is the people that, that we choose to be uh, working with. Okay.

Speaker A: Um.

Speaker B: And in. In. I'm lucky to have to still nowadays I'm very lucky to work with a lot of friends. And um. I know that is not easy sometimes. Uh, it's not easy to, to. To. To make sure that both personal and professional goals live together. But we manage that. But the important thing is we shouldn't be afraid to say no to someone. Okay. And, and that was. I, I actually learned very late. Okay. I I tend to. Okay, so let's give a second chance, a third chance, whatever chance until someone adapts to your environment. And that never ends good. Okay. Of obviously we need to do. Everyone deserves uh more than One chance. But everyone also deserves that someone is, is direct enough to say, okay, there is no more path for us to be together and it's better for both sides that we split. And that was very tough for me, uh, for a long time. And in the last years I gained that skill of being, uh, I mean being uh, respectful, uh, but still pragmatic and saying, okay, we need to end this.

Speaker A: Yeah. Yeah. Because that's also part of your role now. You. You cannot always be kind. Sometimes you also need to be, uh, making a tough decision.

Speaker B: Yeah.

Speaker A: Even with friends sometimes if it doesn't work.

Speaker B: Indeed. Indeed. In the end, what I try to do is, is to remember that is more important. The commonwealth of the whole group. Uh, and uh, the happiness or the wealth of uh, the individual cannot overthrow the common one.

Speaker A: So. Yeah, that's a nice fourth lesson there.

Speaker B: Yeah. Um, it's the best I can do.

Speaker A: And you mentioned the environment that you want to create. Uh, an environment. What type of environment do you want to create? And also what type of people fit into your environment? What, what are, uh, the type of people that you, you seek out.

Speaker B: So first the environment is not mine. And it's, it's belongs to everyone that is there. That. Then that is the first message. So if someone wants to join, it needs to be. To be willing of being part of it, to contribute. It's not like getting the rights and not having the duties, you know. So both things came aside. Right. Um, and so Arthur Zil is a full remote company with the goods and bad things, uh, on it. So we put a lot of effort to build and maintain open culture based on. On the certain values. Things like passion for knowledge, um, respectful, uh, m. Meritocracy, um, on the right good or on the right, um, meaning of it.

Speaker A: What do you mean with it?

Speaker B: So if someone uh, has achieved, uh, some, Some. Some success needs to be rewarded through it. Not only financial speaking, but doesn't make sense, uh, that you don't reward people that do whatever achievement. Okay. So it's very important for us to, To. To make sure that um, that happens. So the, the environment, uh, is being built by everyone. So we have. Luckily we have a very open culture. People contribute, um, even if it is not their, Their own field of expertise. You know, for example, there is funny things like people on, on the business support side. They are, they are. When they arrived towards, they were not that very geek people. Right. Or, or, or. But nowadays because they, they. They speak with others and, and they start to see, uh, their own passions on this kind of things I see people like, I uh, have some colleagues um, that they, they are focused on, on the business administration side but they, they started to do like scripting to automate some of their own duties, you know. And it's very funny how this um, uh, came, came a reality. It was because of this knowledge sharing and, and, and people and, and of course the knowledge is not strict to security or even to it. People speak about their own hobbies and we have internal initiatives to promote that sharing and we also do a lot of gatherings. So besides um, the fact that we are fully remote, we try to get everyone together at least six times per year. Um, two of them with the whole company and the other four, uh, gathering per team let's say. And ah, where we do it like social events, team building on face to face work sessions or whatever. So the environment is being built, the feedback is quite good. So I hope that we go down that road for a few more years now.

Speaker A: Yeah, because it's probably more difficult to protect the uh, culture and the environment if you are fully remote. It's been a bold decision.

Speaker B: Yeah, it was, it was uh, it was. I mean we were so, we artillery started after the pandemic. So the, the world was kind of uh, open to this new idea of being remote. Now I know that a lot of companies are stepping back a little bit going through hybrid modes and so on. But actually remote uh, model is working very well for us. Okay. So people are very responsible. Uh, so we don't have that notion of very strict schedules. I mean obviously if you have a meeting, you have a meeting, you need to respect others, the others that are there waiting for you. Uh, but if you need to uh, do something personal in the middle of the day and you end your work late in the evening, we are all okay with that. Okay. What matters is the work is done, what with quality. Uh, uh, but it's also very important that uh, you get the work, uh, personal and work wise balance. Right. So it's working. It was bold in the beginning but it's still working. The feedback is good so we'll push it for it.

Speaker A: You've hired a lot of people throughout your career for your teams. Now you're already with 50 people. What systems do you have in place and how have you became a better decision maker in hiring the right people?

Speaker B: Um, I don't know if I'm, if I became um, a better decision maker. But I do know that I learned that uh, the human side of it, I mean the values that you can assess um, on the person, uh, that the type of mentality are as important as the hard skills and the soft skills, uh, that everyone is looking through. So actually right now our, the way that we hire people started with an interview that we don't speak about work. Okay. We are keen of knowing that personal as individual, what, what, what that person thinks about life, how, what is pursuing, what are his goals. Right. Uh, and they, they fit with our culture, they fit with the goals of the other people that are already here. And in later interviews we go down to the art skills and soft skills and so on. But we, we actually uh, it's for us it's very important to start on, on the personal, personal respect and privacy obviously. But on, on the human side of it. Let's put it this way.

Speaker A: I love it. I ask this question almost to everybody that's here in uh, in the podcast studio. And what I've noticed, most companies turn that around so they start with one or two technical interview uh, rounds and then the third one is usually with the partner or the director and that's then the cultural fit.

Speaker B: Mhm.

Speaker A: So then at the last stage we're going to talk a bit about do you fit in here with us? But I like it that you start there uh, from the get go actually

Speaker B: for like the first year of Art Gazili we did it like that. So in the end, but then we realize uh, okay, we could have very good technicians, more very good professionals, but if they don't fit into our culture, they will not bring value. So we change and we said okay, first we see if there is a match, uh, uh, value wise and so on. And, and if that happens we go to the second stage and it's working good for the last almost four years

Speaker A: now that's definitely a system that you

Speaker B: uh, like any other, it's ours and it's working. So we are happy with that.

Speaker A: And now you're in a stage where um, the company is operating for five years, you're with 50 people, expanding new markets. What do you have in store with Art Resilia? And in say three or five years, where do you want to be with the company?

Speaker B: People can wait from us, um, an assurance that we will be completely independent. I mean we obviously we use third party vendors and so on, but we will never, never advise anything rather than what fits better to the customer. So that is quite, quite uh, part of our signature. And it will keep being that way because I mean we believe that that is the only way to build uh, true security. Secondly um, we put a lot of uh, of um. Uh, I would say we, we. We try to do everything in a very knowledgeable way. So um, it's not. Sometimes we are not good in Martingale or as. Not as good as we should do. We should be because we try to do it things in a very technical way, supported with a lot of technical knowledge to achieve high quality. That is also uh, a part of our signature. And at last we try to innovate and adapt to what threats can appear in the future. Okay. And that is why we are looking now for digital sovereignty. Because we believe that that will uh, be like some sort of driver more uh, common, especially in Europe. Um, and also we are trying to expand our capabilities uh, outside uh, the service providing itself. So uh, like I said, we are developing technologies to, to automate and to improve our service delivery. But we are also looking into other startups that have very good uh, and sovereign technologies uh, that could help us building this sales pitch that we believe.

Speaker A: So more in partnership also. Yeah, yeah. It comes back to the previous company where you had I think nine different security vehicles at some point. Right. That you really became a group.

Speaker B: Yes.

Speaker A: Is it the ambition to become a group again?

Speaker B: Uh, I don't know, maybe in a different way. Um, so uh, it was a good experience being part of a huge corporation. But I don't think we will repeat that. We are more a kind uh, of startup guys. So we prefer more, we like more uh, informal environment, uh, and, and so on. And so if, if that comes to be reality, being a group, it will be a different kind of group for sure.

Speaker A: And for Art Brasilia is, is AI. Is it a, is it a bless or a curse?

Speaker B: Um, neither I would say. We, we see this latest advent of, of AI the gen AI very conceptually speaking, very similar to the previous ones. Okay. It's a new tool. Okay. Uh, conceptually speaking, very useful because it will uh, improve performance, it will help on differentiating, it will uh, for sure optimize a certain type of tasks and procedures, but it will not change the world. It will not. Okay. I remember that in the early 2000s, uh, a very nice company called Net Canvas, they put it in the market, the first tool to automate pen testing. And actually they had this feature of auto, automate exploitation of a certain vulnerability. And the market was obviously the market was much smaller then, but even the hypes were happening. So people were oh, this will change everything. I will lose my job. I will not be a pen tester anymore. Because in five Years from now these tools will take my job of that didn't happen and it will not happen with Gen AI either. At least I don't think so. In art zeal we are using AI in a lot of things to automate our duties, to do double checks, to support the knowledge sharing in a lot of perspectives. But as, as a tool it's a very important tool. We need, need to be guided, need to be used with common sense. But it's not more than that and

Speaker A: from an educational perspective because I think you have always been given back a lot and I uh, think you've been also affiliated with, with the university and you're also part of the EC Council as an uh, advisory member. So, so I dare to say that uh, education uh, is something very important to you. What would you advise young professionals now that want to start a career in security and also from self learning, um, looking at AI, what would you now do? Say you're 16 years old. What would be your entry into a successful career in this uh, in this market?

Speaker B: So for the first question I would say that remember, remember that the most important thing is always knowledge. Okay? More than certifications or graduations or even networking. Because having the knowledge, it will open all those doors for sure. Okay?

Speaker A: So but is that knowledge from, from the textbook or is it experience?

Speaker B: Both. They are different kinds of knowledge. Both important. They will help you in different situation situations. But in the end is uh, the way of knowing the world and being capable of interacting with it. So as much knowledge as you have as better you will be. Okay?

Speaker A: Is it not because of AI that knowledge is no longer a differentiator? Like knowledge is freely, more freely available than in your early days.

Speaker B: Um, yeah, I mean m. It's easier to access the knowledge, it's faster. But I, I don't think that um, you don't need it anymore. Okay? Uh, probably you need different kinds of knowledge. Okay? Even to use geni in the proper way. It's, it's a knowledge itself. You need to know the underpins of, of LLMs to actually take the best value out of it. Right? To, to, to. To use a certain bot to a certain type of duties, to uh, um uh make a chain of bots to achieve a certain goal, whatever, you know. So, but so I would say that will not make you uh, um, it will not uh, block or avoid uh, the importance of knowledge. Uh, Gen AI will just increase the, the scope of knowledge that you, you need to have.

Speaker A: Yeah.

Speaker B: Yeah. So the second question is AI will open or Gen AI Will will open new doors as every new disruptive technology. So be aware uh, try to see uh, if out of those new topics there is something that you like and dig in. Be an hacker.

Speaker A: Yeah, I like that. With your journey so far, I think we said it in the beginning also that you have a nick of spotting like a new trend. So the incident response was something unknown. MSSP was not a word yet in Portugal when you already had a big team of people working in an mssp. Now you decided on art resilient, the resilience and that became a big thing. I see it in a lot of big organizations that they have a cyber resilience team. Now it's the digital sovereignty which is a huge topic and I think that's only going to grow also the next year. So I think it's good that you're going to ride that flow. But I do think AI uh and AI security is also going to be like a thing that's going to blow up.

Speaker B: I do agree, I do agree. Yeah I do agree. But even if it will blow up in my perspective it always be or it should be as a tool that uh, optimize human capabilities or amplify human capabilities. It will not substitute human.

Speaker A: Yeah. Ah.

Speaker B: At least for the, for the next two decades or something like that. I mean AI evolved uh, in, in a set of advanced design. This should be the fifth one. Right? Uh the fifth big big big one and and obviously the other ones, the previous one didn't have the same impact because now is more the, the access to this, this uh gen AI is more democrat. Democratized. Right. So it's being used by everyone, not only techn technical people. But even though uh, it will not substitute men people for sure.

Speaker A: No I agree there especially for the next coming years and the way we have this conversation and if you go to an event or you have a sales meeting it's also about working together.

Speaker B: Yeah.

Speaker A: And, and people do business with other people. I think also when there's a deal, I think both sides hope to have a win win and otherwise you don't do business again with each other.

Speaker B: Yes.

Speaker A: So I like that uh, in your story also that you, you still collaborate with friends so you know which people you want to work with.

Speaker B: Yeah.

Speaker A: And I want change that.

Speaker B: Yes, yes. Actually I just remember a story that is quite similar to what is happening now. So 20 years ago there were two types of pen testers. The ones, the senior ones that uh, had a lot of expertise on pen testing systems and networks and so on and, and the youngest ones that were starting to testing web applications, that new thing, you know, and, and, and it's basically the same that is happening now. So I would say that people that wants to survive to this new paradigm and be an expert on it needs to not only be a uh, good uh, pen tester on systems and networking, but also learn pen testing on uh, web application meaning use AI as much as you can, uh, or in security for testing for operations or whatever. Uh, but don't forget the, the other layers of knowledge that you need to have.

Speaker A: Yeah, nice, nicely put here. So remember where we come from and adopt the new skills as well.

Speaker B: Exactly.

Speaker A: Yeah, exactly. No, nice. This has been a super, super interesting conversation, wide ranging and it's uh, super nice to, to speak with a founder from Portugal, also known how m progressive. I think Portugal and, and Spain are also with uh, together with Denmark on, on the digital sovereignty part. So I think it's very good that we have European founders that, that have a Europe first idea mindset. So I uh, I'm very inspired. I look forward to following the journey in the next couple years. And we always end this podcast with the same question. Uh, so here it goes for you as well. If you can send one signal message to all the CISOs across the world, what would this signal message be? Whoa.

Speaker B: Um, don't forget that there are two types of confidentiality. The one that is business wise and the privacy of people that is building and running the businesses. And we need to protect both otherwise we'll never have data privacy, data confidentially, whatever. And in my perspective all the attributes out of security confidential will wall, uh, confidentiality will always come first.

Speaker A: Can you go a bit deeper on that?

Speaker B: So it's uh, especially for roles like tightly related with the architectures and so on, it's not easy to balance these two requirements sometimes. Okay, so uh, one thing is protecting um, the goals of the organization to keep the their own data confidentiality, their own intellectual propriety and so on. Uh, but another thing is to make sure that you protect the privacy over your users. Right. Um, and in the end of the day I believe that privacy, the individual privacy will gain a lot of relevance in the future. So for a business to evolve it will need to balance both things. Otherwise your user will not adapt the technology, you will not use it and you will don't do, you will not do businesses. So and sisu's are the key people on, on this decision. Right. So be aware of that.

Speaker A: Yeah, it's a very good message. I feel maybe there's uh, your. Your next venture again, privacy for the individuals.

Speaker B: I don't know. Maybe. Maybe.

Speaker A: Okay. Francisco, thanks so much for joining us. It was a real pleasure. Thanks for listening to this episode. Don't forget to, like, subscribe and share. Stay safe, stay curious, and until next time, in the district.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Zalando Deployed GenAI Without Handing Attackers the Keys with Florence MottayCyber Leaders · on Cyber resilience87 / 100
  • Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee RosseySecure & Simple · on Incident response86 / 100
  • Pursuing strategic partnerships to tackle Cobalt Strike abuseHealthcare Strategies · on Penetration testing85 / 100
  • “An AI-Enabled World.” Why You Can’t Avoid Building AI Into Your Practice | New SoloLegal Talk Network · on Digital forensics82 / 100
  • Chris Pogue: Digital Forensics in the Modern Threat LandscapeKitecast · on Digital forensics82 / 100
  • 401 Access Denied Podcast Ep. 120 | Bridging Borders: How INTERPOL Tackles Cybercrime Worldwide with Craig Jones401 Access Denied · on Digital forensics82 / 100

More from Cyber Security District

All episodes →
  • Automating the Boring Parts of Cybersecurity Consulting | Leslie Clement & Erie Berhitu, Clember AI | Cyber Security District
  • How Hackers Bypass MFA: The Rise of Infostealers with Tom Leijte, Founder of Passguard
  • Building Human Resilience for Deepfake-Driven Phishing | Julius Muth | Cyber Security District Podcast
  • Securing the World´s biggest HR Firm | Martijn Nykerk, CISO at Randstad | Cyber Security District
  • From Fintech Founder to Cyber Investor with Chris Zadeh | Cyber Security District
Explore the best B2B Engineering & DevTools podcasts →
All Cyber Security District episodes →