Cybersecurity Ecosystem Show · 2026-04-30 · 32 min
Key moments - from our scoring
Substance score
62 / 100
Five dimensions, 20 points each
Chad Lovin, VP of OEM Partnerships at Reversing Labs, breaks down what makes an OEM partnership work in the cybersecurity ecosystem. An OEM partnership requires two criteria: the vendor provides an API, SDK, or underlying engine (not the full product as-is), and the licensee embeds it into their own product. For smaller or established vendors without Cisco or Palo Alto's market presence, OEM is a powerful go-to-market channel because the total addressable market is tightly defined - a few hundred large cybersecurity vendors rather than tens of thousands of enterprise customers competing against major players. Lovin covers the relationship between technology integrations and OEM deals, noting that successful meet-in-the-market integrations often lead to OEM licensing opportunities. He emphasizes the importance of standardized APIs (like Reversing Labs' publicly documented endpoints) and SDKs for OEM success, and warns against products heavily embedded in business workflows that require customization. Critically, he advises on pricing mechanisms - particularly floor unit pricing in royalty models - to prevent partners from discounting your technology to near-zero while underpaying royalties. The episode addresses common pitfalls including custom development that doesn't scale, investor perception of OEM revenue as lower-value than enterprise revenue, and cannibalization risks when OEM partners effectively replace your direct sales.
An OEM partnership involves the vendor providing APIs, SDKs, or underlying technology engines that the licensee embeds into their own product. Resellers and MSSPs buy the full product as-is and resell or manage it; OEMs take the underlying technology and white-label or integrate it into their own offering.
Threat analysis, threat detection, and threat intelligence products that have standardized APIs and SDKs tend to work best for OEM, because they can be consumed in a standardized way without requiring heavy customization per end-user or deep tailoring to business workflows.
Include a floor unit price in OEM contracts so that licensees can't discount your technology to near-zero and then report minimal royalties; this is especially critical in rev-share or per-unit royalty models.
Yes; successful technology integrations often lead to OEM opportunities and help remove sales objections in the enterprise channel. Vendors should proactively build integrations with major platforms even without confirmed joint customers, as visibility and out-of-the-box functionality drive customer adoption.
Investors may perceive OEM revenue as lower-value because the vendor's brand isn't directly visible to end-users and the technology is typically discounted to embed in partners' products, though this perception doesn't always reflect the true strategic value of OEM for market access and credibility.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains useful operational guidance on OEM structures, deal mechanics (royalty models, floor pricing), and product fit criteria. However, it relies heavily on anecdotal war stories rather than systematic frameworks, and spends considerable time on basic definitions and context-setting. The practical insights (e.g., standardized SDKs, avoiding high-touch customization, revenue concentration risk) are valuable but scattered throughout rather than densely packed.
if you don't have your product productized in a form where you can have standard published APIs...if you don't have those two things, your product is probably not a good fit
you really want to make sure that no single OEM is going to be more than 10%, ideally no more than 5% of your overall revenue
The core framework (OEM vs. MSSP vs. channel) and advice (standardized APIs, avoiding custom builds, revenue concentration) are sensible but not particularly novel in B2B SaaS/software partnerships. The anecdotes about Yahoo Toolbar and DLP provide some color, but the underlying principles are fairly standard practice. The distinction between OEM and technology partnerships is useful but not groundbreaking.
criteria number one...they are taking our APIs, our SDKs...criteria number two is that they are embedding your product in whole or in part into their product
You go to war with the army you have, don't try to invent a new army once you've started the war
Chad Lovin brings legitimate depth: 20 years in OEM/partnerships, hands-on roles at multiple companies (small startup, NetWitness, Reversing Labs), and exposure to both inbound and outbound OEM. He has executed deals and learned from failures. However, he is not a household name, has not built a major platform from scratch, and his perspective is largely tactical/operational rather than strategic/visionary. Solid practitioner but not a marquee guest.
I've been with Reversing Labs for a little over a year. Although I've got a long history with them. I've been on the other side of the table as a licensee, licensing them inbound for oem, partnering with them, um, competing with them
I've lived, ate and breathed [OEM] and have done so for 20 years
The episode includes some concrete examples (Yahoo Toolbar, NetWitness/Reversing Labs deal, DLP product failures) and specific deal mechanics (seven-figure Yahoo contract, 25% revenue concentration scenario, $50/year per-user pricing hypothetical). However, most numbers are round/anecdotal and lacking precision. No data on OEM market size, adoption rates, or performance benchmarks. Many claims remain general ("a couple hundred large OEM cybersecurity vendor prospects") without supporting evidence.
it was Yahoo at the time, uh, paying us seven figures, which was for us was enormous
we had 25% of the revenue...generated by a single OEM
The host asks reasonable follow-ups and does probe into details (floor pricing, product fit, differentiation from MSSPs). However, the questioning is largely receptive and confirmatory rather than challenging. The host seldom pushes back, tests assumptions, or ask harder questions like ROI impact, failure rates, or whether OEM is a crutch for weak standalone products. The conversation meanders somewhat and occasionally goes off-agenda without discipline.
Very cool for your perspective...I'd love to hear...just curious your thoughts there
Fascinating. That's so interesting. I love the derivative aspect
Computed from the transcript - who did the talking, and the words that came up most.
The threat intel in your SIEM, the scanning engine in your endpoint tool, the analysis powering your detection platform. There's a good chance those capabilities come from a company you've never directly evaluated. That's OEM. And it touches every corner of cybersecurity. Chad Loeven has spent 20 years building OEM partnerships on both sides of the table, licensing technology inbound as a buyer and outbound as a seller. In this episode, he breaks open one of the most misunderstood parts of the cybersecurity market and explains how it actually works. We get into what qualifies as OEM versus resale or MSSP, why OEM can be the smartest go-to-market path for startups, and the real stories behind deals that worked and deals that didn't. Chad shares the seven-figure Yahoo contract that nearly drained his company, the DLP product that proved some solutions just don't OEM well, and the time he walked into a company where 25% of revenue disappeared overnight because of a single OEM dependency. But this isn't just a conversation for partnership teams. If you're a practitioner, this episode explains why some capabilities in your stack feel native and others feel bolted on.
Transcribed and scored by The B2B Podcast Index.
Speaker A: I had Chad Lovin here today. Hey, Chad.
Speaker B: Hey, how you doing, everyone?
Speaker A: Thanks for being here, Chad. Looking forward to our conversation. We're going to talk all about OEM partnerships and we've done an episode on this with, uh, a panel previously, but I think it's still, uh, a black box for most folks. And so I'm excited to talk to Chad all about OEM partnerships and what that means for cybersecurity partnerships in the whole ecosystem. Before we jump into that, Chad, I'd love to hear, uh, tell me about your current role and your current responsibilities.
Speaker B: Yeah. So thank you very much first of all for inviting me, of course. And love to talk about something that I live, eat and breathe and have done so for 20 years, to be, to be honest. And currently, as you can probably tell from my badge, uh, there I'm with a company called Reversing Labs, uh, based out of Cambridge, Mass. Boston. Basically. Reversing Labs is basically in the threat analysis, threat detection space where a, uh, claim to fame is way back when, and this is going back about 15 years ago, we developed one of the, what is still, I think, the best, what's called static analysis tool for malware. And over the years our team has built around that core offering into a pretty broad range of threat analysis and threat intel solutions and software, supply chain security solutions. I've been with Reversing Labs for a little over a year. Although I've got a long history with them. I've been on the other side of the table as a licensee, licensing them inbound for oem, partnering with them, um, competing with them. And so now here I am in the relatively new seat for the last year, driving their OEM business. You know, we call it partnerships, but part of it is, you know, essentially carrying a bag and licensing our stuff to outbound OEMs and also handling technology partnerships. So, you know, I'd love to talk a little bit today about, you know, the interplay of, you know, meet in the market, technology integrations with, you know, the cell 2oem cycle. Uh, and that's, that's essentially what I do, uh, within Reversing Labs, you know, where, you know, our overall icp, you know, ideal customer profile is generally large enterprises, blue and private. And a very large portion of our customer base is other technology companies. I can't name specific names, of course, but you know, them. Um, most of the major technology vendors in some form or another are ingesting our threat intel, if not our analysis tools or some combination to enhance their own coverage. And Detection.
Speaker A: Very cool, Chad. Thanks for the backstory. Super interesting. I'm looking forward to. I know we're talking right before about, uh, the connection between technology partners, um, and whatnot. I'd love to hear you maybe answered it a little bit, uh, already. Um, how in your, in your world kind um, of break down. What does an OEM partnership look like and why is it so important? I know there's so many, especially in our last conversation that I did, uh, with some OEM leaders. They both had very different OEM strategies. One was in bed, and I'm still a little confused, honestly, of the different options. So tell m me about, in your world, what does an OEM partnership look like and why is it so important to your overall go to market?
Speaker B: Yeah, I think one of the fundamental definitions is, uh, anytime the customer is doing two things, they are taking not the product as is, but, you know, something underneath, like the engine, so it's getting reskinned or you're getting an SDK or using APIs. So that's criteria number one. And then criteria number two is that for them to be an OEM, it's because they are, in some form or another, embedding your product in whole or in part into their product. And so if it meets those two criteria, then it's oem. Otherwise, you know, it could. You know, we were talking about MSSPs before. There's obviously a bit of a gray zone with some MF. Some MSSPs, you know, could be considered OEM, but either way, you know, anyone else would fall into the MSSP bucket or a resale bucket. Um, and of course, the typical enterprise end users. So my focus is the people that meet those two criteria. They're taking our APIs, our SDKs, and they have their own product. Not necessarily a security product, but most of the time it is a security product where we are essentially powering or improving their coverage of what they do in the cybersecurity space.
Speaker A: Very cool for your perspective, especially talking to maybe an audience that is looking at all sorts of partnership opportunities. Why is OEM in particular so powerful or so important, or what have you learned? You know, working in this space, you're like, wow, this is just the power of it, the uniqueness of it. Um, and yeah, just curious your thoughts there.
Speaker B: Yeah. Uh, so it's not for everyone. It's not every company wants to go down the OEM route. And sometimes companies, uh, grow out of oem. Uh, uh, you know, you see that, uh, quite frequently as well. Uh, or sometimes the. You Know, depends the winds change. You know, CrowdStrike I think is a very good, very public example. They've gone in and out of OEM recently. Um, they've, they've gotten back into it. They've decided that it's, it's important for them to have a dedicated team gotten quite aggressive in terms of, you know, also licensing their technology to other technology vendors. But I think a more common trajectory is that if you're relatively small, you know, you don't have the Cisco Palo Alto kind of presence in the market, sometimes OEM is a good way to build up a revenue stream, to build up credibility in the market and a way to access customers you just couldn't possibly reach otherwise. Right. You know, because one of the beauties of the OEM space is, you know, it's a very tightly defined, you know, tam, you know, total addressable market. There's a couple hundred, you know, realistically, you know, large OEM cybersecurity vendor prospects out there. Pretty easy to figure out who they are and who the people are within those companies, as opposed to say if you're selling into mid market enterprise, well, all of a sudden, you know, that's tens of thousands of customers and you're competing with Cisco and Fortinet and Palo Alto and everyone else. So I, uh, think for a startup, even m relatively established startup, which certainly would be the case with Reversing Labs, that's one of the solid business cases for pursuing oem. But you know, there's always caveats so that that's probably the time to talk about what kinds of deals you don't want to do. You know, it's always important to know which customers to fire. And that's true of OEM and enterprise, of course. So yeah. And I'm sure you've had similar experiences, not necessarily in oem. Right. But there's customers that when you do the math and you really look at the cost of supporting them and bringing to market, you come away and say, well, that wasn't really worth it at the end of the day. And anecdotally, you know, when I first got into oem, this is again going back almost two decades ago. I landed at a small company in Florida that had what at the time was a huge, huge contract for, um, you know, I think I can say it was, it was Yahoo at the time, uh, paying us seven figures, which was for us was enormous. That was, that was like huge. It wasn't a good deal. It was the single largest customer we had. But what was killing us was all the custom changes that they were asking to get made on the product that we couldn't really apply to anyone else. So we ended up essentially forking the product and having a dedicated team and probably didn't break, you know, at best broke even on that contract if we were lucky and it didn't end up being a great deal for the company.
Speaker A: Fascinating. I've heard similar situations on the enterprise side too or experienced that where you know, the enterprise needs these, all these custom solutions that don't, don't apply to other enterprises and you end up getting sunk. Uh, that's so fascinating. I'm curious from your uh, perspective. Um, we're going a little off agenda here, but like what sort of, maybe even in cyber or just what you've seen in general, what sort of products embed the best. Have you, have you noticed like a trend of like. Yeah, I'm just curious, especially for early stage founders and whatnot, is there, is there a type of product or maybe I'm not even asking the right question, but is there, is there like a, is there, is there product. Other types of solutions that are like for like threat analysis, right? Like for your current company, that makes a lot of sense. You could use that data, you could use that and that could be applicable, um, and can be used um, and white labeled or be OEM very easily. Just curious if any thoughts on that from like a product standpoint?
Speaker B: Yeah, it's a good question. You know, I can only talk about my somewhat, you know, limited, well defined experience which is always around threat analysis and threat detection, which does lend itself to your point to uh, oem, because you can have one of two or both things that I think are very important. You know, very standardized API and a standard SDK. So if you don't have your product productized in a form where you can have standard published APIs, like in the case of reversing labs, you can go to docs.reversinglabs.com all our APIs are there, right? You know, just, you don't even need an NDA. It's everything's right there. So if you're looking at incorporating our product in your product, you can figure it out beforehand before you even contact us. Or an SDK. Of course, if you have to run something on the machine, if you don't have those two things, your product is probably not a good fit. Like that's, that's the number one. I think more generally I don't know if there's any, any high level exemptions but you uh, know what you know. So whether we're talking like identity validation, the threat analysis, threat detection, any of those kinds of things, you know, you were talking about grc. I would say again very much my own personal bias experience. The more your product is involved in business workflows and that kind of thing and requires tailoring to be functional for the end user, the less likely it's going to be a good OEM solution. Again, you know, threat intel, you know, there it is, you know, like there's different feeds and all that kind of stuff but you're not actually sort of tailoring per end user or the end user can do that themselves without us even being aware of it.
Speaker A: That's fascinating. That's helpful. Thank you for sharing. That's, that's super interesting. Um, very cool. So I'm curious going kind of back to the why it's important and the differences there. So it sounds like obviously like the opportunity, especially for early stage like you mentioned the ability to, to, to access a large customer base. The ability. How is that different from your perspective from other partnerships opportunities like going to MSSP or, and uh, or going through tech partnerships or. Which I will talk about in a second. Have you noticed any benefits that the OEM has that a channel motion doesn't have outside of the ability to access customers and have that credibility?
Speaker B: Yeah, good, um, question and you know there's a multi part answer to that I want to flag. You know another downside which isn't a golden rule but it's just something to be aware of if you're an early stage company is that in investors sometimes will value OEM revenue less than enterprise revenue. Yeah, for, for. I don't necessarily agree with the logic but the logic is essentially that it's not your brand that's out there and you are essentially discounting your technology to get it embedded with the oem. So there's something valid, valid points but I don't think it's necessarily true but just something, something to be aware of in terms of how you go go out for it and understanding also how your own investors or potential investors may value that revenue versus to your point, um, revenue generated through MSSPs or large enterprises. But uh, I certainly, I'm a big fan of the MSSP channel by the way for a lot of the same reasons as oem. I mean it's very adjacent and you know a lot of the market, especially outside of the Global 2000, I mean you know mid market SMB is heading towards going through MSSP slash MSP channels. So I think everyone has to have a plan for that or take a good look at it if they, you know, have good reasons for not doing it, I guess I would say. But, you know, you mentioned another, another one, another aspect which is, you know, how does this stack up against, say, regular channel partners and also technology integration partners? I think it's very complementary to channel partners, you know, again, excluding the MSSP space. Orthogonal, really, so one doesn't preclude the other. Although, um, um, you know, I will bring up another sort of risk factor in the calculation is you want to make sure you're not OEM in a way that's going to cannibalize your own sales. That's definitely, uh, a risk. We factor that in by essentially making sure that we're not licensing on an OEM basis to people who can publish our feeds or analysis tools on a standalone basis. Right. So in other words, if it's a, uh, derivative, what we call a derivative data use case where we are enhancing the total solution value, but we're not the entire solution value, then that's generally okay. And of course you wouldn't, you know, you want to avoid someone who's too directly a competitor. You kind of screw competitors altogether. There's always going to be a little bit of everyone competes with everyone at the end of the day. Right. I mean, like, so, you know, I would say two thirds of our OEMs have some overlap in theory or in practice in some way in some circumstances with us, but that's, that's life. I think we still come out ahead.
Speaker A: That's so cool. That's so interesting. I love the derivative aspect and thinking through of the version they get, the outcome they get through the OEM versus what they can get through you direct and making sure that doesn't cannibalize it. Is there anything else on the cannibalization side that you. That that's worth noting that that should be mentioned?
Speaker B: You know, I've, I've certainly, I haven't had too many bad experiences, although I know a lot of, you know, peers who have had some negative experiences and have had to pull the plug on contracts because the licensee didn't act in good faith. You know, like, uh, there's a lot of good faith in oem, right. A lot of the times you're basically dependent on, on the OEM M licensee giving you a report and you know, you trust it. You of course contractually have the right to audit. But going and auditing is a, is A is a pretty pretty much close to the nuclear option. So you trust, hopefully maybe you verify, maybe you don't. And every now and then you do get a bad actor who is underselling your product. And there's, you know, there's caveats and you know, more than happy to engage with any of your listeners. Listeners, if they want to know some of the caveats that you need to have in these kinds of contracts to ensure that, you know, essentially they don't use your product to subsidize their own product. In other words, are not underpaying you in order to sell your solution at a low price, in order to get a higher price for their own proprietary product. You know, that's, that's a big no. No, of course, not necessarily cannibalization, but cannibalization adjacent, I guess you would say.
Speaker A: Yeah. Is there any caveats you're willing to share now? Just anything that comes to mind.
Speaker B: Well, really, essentially having floor pricing, if you, if you, if you're doing an OEM license, uh, you know, I mean, essentially everything falls into one of several buckets. And in terms of royalty models with oem, right, you, you might have a blanket annual fees, you might have tiered volume pricing, or you might have a rev share. If you have a rev share, then you also want to make sure, or a flat annual fee. In either scenario, you want to make sure that there's a floor unit price that the OEM is obliged to charge to their customers. So that way they don't. The OEM doesn't have an incentive to essentially discount your stuff to almost zero and then give you the royalty report. Say, well, you know, we had to kind of give it away, so you get almost nothing.
Speaker A: Interesting. Oh, wow. It's good insight. That's great. Well, let's talk about the diff, uh, how technology partners and how they relate to oem. So first, if you, um, don't mind defining how your definition of a technology partner, I'd love to hear that. And then how do they relate? How do they work in tandem?
Speaker B: Yeah, um, again, something I'm very passionate about and the definitions is that where you have an meet in the market integration. So they are not reselling your stuff, you're not reselling their stuff. Or at least that's not the primary go to market motion. There's no, there's no white labeling, no nothing. It's just simply, you go to your common customers and you say, you know what, our stuff works together. And here's the proof, you know, like maybe There's a, uh, that's an SDK kit, a little kit that Python script or whatever. Maybe it's just out of the box. The more out of the box it is, the better. But I'm always a big fan of coupling that with the OEM function in the business because those meet in the market. Integrations often lead to oem. Right. Um, if it's a successful OEM or sorry, a successful technology integration and they're finding that, you know, there's a lot of joint demand, that's often, often, ah, you know, a good indicator that, hey, maybe we should just bundle this and offer this to our customers. Um, it's also a huge boon to the enterprise team because, you know, it gets rid of a huge objection in the sales motion. Right. Every enterprise customer is going to have splunk or cortex or whatever, you know, out there. And so you need, you need, there's a list, a library of, you know, 20 or 30, you know, SIM sort integrations, what have you. You just gotta have these days, of course, Azure, uh, Sentinel, anything AWS related. If you don't have those, even if you say to the customer, hey, you know, you can just write your own script, the customer's gonna be like, ah, uh, why would I write my own script when your competitor just, you know, has it all working out of the box. So really, really important to get those objections out of, you know, removed from the enterprise sales cycle. And you remove that by, you know, proactively working with your technology partner. And I'll add something anecdotally that I've, I've often found is an objection internally to getting these integrations done is uh, the number one pushback will, will be, well, we don't have a joint customer, but that's a survivor bias in my opinion. You know, you're only going to see those joint customers who are actually so committed that they're going to be like, yeah, yeah, I really want this and this is worth the hassle. So what you're not seeing is all the not committed customers who just looked at your spec sheet, they looked at your partner pages and like, yeah, uh, you know, I didn't see cortex or whatever on your list, so I'm going to move on. You never. They've just drifted off into the night and they've bought a competitor's products. I think you need to be proactive and take a shot in the dark and build up that library of integrations. And yes, you know, half those integrations may not get used. That's the Reality. And somebody, you know, could be a stickler and say, well, we wrote that integration and nobody ever used it. True. But there's probably going to be many more integrations. You did write and you did support and that did serve. Did exactly as they were intended. And you know the old expression, you know, half the money in advertising is wasted, but you just don't know which half.
Speaker A: Yeah.
Speaker B: You still advertise and by the same token, you still gotta do those integrations.
Speaker A: Fascinating.
Speaker B: That's.
Speaker A: So, yeah, you're. Well said. And I think even the perception that you don't have the integrations can be. Is half the battle. And uh, and, and yeah, half the, Half the upside. Um, tell me about the journey from technology partners to oem. What does that look like? What, what, what are some key things you've noticed as like, okay, this, this could really OEM partner. Um, and yeah, when should you consider that from. If, uh, you have an integration with an organization now already?
Speaker B: Yeah, I don't know that well. Yeah, well, I've been on both sides of that, actually, come to think of it. So it's when, um, so I. To give you an example, actually, when I was on the other side of the table with, uh, with. As a customer of Reversing Labs. So this is, you know, at, uh, RSA for those of you who remember RSA, uh, NetWitness. So we were, we ended up licensing, Reversing Labs into the Netwitness product. And that was partly driven because, uh, the integration was good. That was fantastic. Customers like that, but they really, really didn't want to even have to piece it together like this. They were saying, uh, you know, we just need this. Like, we want to fire up the box, we want to fire up Netwitness, and we want to see that we've got this threat intel enrichment there. Maybe we'll pay extra for more enrichment or higher volumes. That's fantastic. But give us something, you know, just make it useful straight out of the gate. And so, so that was the driver when I, when I was on, you know, the inbound OEM side to, to say, yeah, we, we've got to have this. And so that's. That I think is a fairly typical motion. Now, of course, the OEM provider themselves doesn't necessarily have that visibility, so the OEM provider has to poke and ask and try to dig that up. If you're lucky, you'll have some metrics, like you'll see the number of downloads or the number of activations or what have you. But sometimes you, you don't have that depending on the nature of the integration. So it's really just a question of keeping tabs on those joint customers out there, either directly or, you know, through your OEM partner or integration partner.
Speaker A: Very cool. Thank you so much. I'd love to kind of switch gears a little bit and just talk about. You've hinted at this a little bit in regards to, um, what kind of products work well for OEM and even the journey from tech partners to oem. But I'd love to hear what are some like, key fundamentals, some key ingredients you think make a successful OEM partnership. What are the things that are like, hey, these are the biggest things to make sure you have in place to make sure this partnership works well.
Speaker B: You know, there's, there's an intangible corporate culture thing, right, where you, you, you have a partner on the other side who understands the value of the technology and the value that the combined solution brings to, to market. So, you know, that's not always the case, of course, you know, if you're dealing with a prospective partner, really views it as a checklist item, views it all the same, you know, everything's the same and they don't see it as, you know, something that distinguishes them in the market. Well, you might, you might get the deal, but you're going to get beaten up on price and it's going to be a commodity thing and nobody's going to be super excited about it. You know, it's going to, you're going to do it, it's going to get signed and it's going to sit there. So you want to try to gauge as well as you can as you go through the motions of engaging with the partner, um, what, what does this finished solution look like in terms of the total value proposition of their solution to their customer. So it really, really behooves you to, to understand what they do, how they're doing it and who they're selling to.
Speaker A: Very cool. Anything else that comes to mind that ingredients that you would, you would, uh, some of the culture obviously, and that alignment, that excitement that they see the value in, in the product they knew it's going to serve. Anything else?
Speaker B: Well, just related to that, it's certainly, I found it very challenging to um, OEM into even relatively large solution providers, you know, software vendors whose market, their end user market is say SMB or consumer. Right. Because unless they are very, very big, if they're selling into that SMB consumer space, you know, they're, they're getting $10 a, you know, a desktop or $30 a year subscription or whatever per customer. So they're really looking at it like that. And every, every penny counts, you know, the cost of goods. So those can be challenging uh, to deal with those kinds of customers. So it really comes, you know, I'm probably saying the same thing, just a slightly different way that you really got to um, understand well who your OEM prospect is, who they're selling to, what they're selling and how much value are you bringing. Uh, because you know, sometimes that translates into what is the right formula. Right. If you get into like a rev share formula and for argument's sake they're going to charge 50 um, bucks a year per user for this feature that is going to incorporate your solution. Are you providing 20% of the value? 10%, 40%. So it's a little bit subjective, but you need to be able to have a sense of that and also be able to argue back to them why you're really providing 30% versus 5% because that's going to translate into what your royalty is.
Speaker A: Fascinating. That's so interesting. That's uh, a completely different kind of angle that you'd have than really any other partnership. I can't think of another partnership that has that kind of dynamic where you're looking at the total price and you're working your way backwards versus like channel you're giving them a cut of the total. Yeah, it's fascinating. It's very different. Very cool. I'd love for you to kind of share a story. You could obviously leave out the names, but let's start with an example of an OEM partnership that failed and like, you know, I apologize for this in advance. But go to that story, that situation that haunts you to this day that you're like, that was so painful, that was so hard. But I learned so much from it. Right. And I would, I want to share with folks what I learned. If. Does anything come to mind when I, when I asked you that?
Speaker B: There's a few of them, I think I can name them because the companies, everyone's moved on.
Speaker A: Uh, sure.
Speaker B: Over the years. Certainly one of my initial ones was not my deal, but I inherited it was when we were licensing to Yahoo. And it's actually, and this is really dating myself. Do you remember maybe this is probably even before your time, Taylor, but the Yahoo Toolbar.
Speaker A: Yeah, Yep.
Speaker B: Yeah, the freaking Yahoo Toolbar. So we, we had a seven digit business licensing malware, scanning into, into the Yahoo Toolbar. So we were powering interesting the malware scanning. But to my point, even though Yahoo Was of course a big company even back then and, and really a giant compared to us, you know, the cons, there was a consumer business. It was very much a freemium model.
Speaker A: Right.
Speaker B: Obviously everyone got a free toolbar and then they hope to upsell you on something or other. Yeah, really, you know, they, they were watching obviously their cogs very tightly. Very you know, difficult uh, for an enterprise company to build a consumer product and meet all the requirements of a consumer product. You know, multiple browsers, multiple languages, this, that and the other. So that's where we, we ended up um, getting sucked into a quagmire ah. Of you know, endless development cycles and, and really had to sort of pull ourselves out of that at one point. I would say another one more recently was for. To your point earlier point about products that don't oem. Well, um, I was with a major vendor where we had a dlp, a data leakage protection product. Um, so my experience on that is DLP does not oem. Well, that's, that's one of those ones where it's so such a high touch product. There's so many specific requirements. It's not quite grc, but you know, every enterprise has different things that they want to customize. You know, do they add, do they care about credit card numbers, birth dates, you know, what format of the birth date, you know, the social insurance number or whatever the ID is in whichever country they're in, the language problems, the different platforms. It's a terribly difficult product to support even if you are directly supporting the end users. And then on an OEM basis, uh, it becomes, became certainly a very frustrating experience for everyone. Again, multimillion dollar contract. So on the face of it, this is wow, this is fantastic. Huge, huge money for everyone. But you know, when, when you have development teams tied up, um, trying to get things to work and customize and tailor, that money starts to get you know, drained away pretty quick and, and the uh, economics of the deal start to look pretty, pretty terrible pretty quickly. So, so that was one, uh, another one where I, my job was to unwind the deal. So you know, sort of put myself out of a job a little bit. So I would say those are the two worst experiences I've had. Other than that, I mean, I think I haven't had too many very negative ones. And I think you know, just because with enough years in your business you do I think get fairly good at triaging who is going to work out here or not.
Speaker A: Yeah, Fascinating. I'm just curious real quick before we move on to the positive stories, um, I'm curious, what, uh, what, what were the signals for either Yahoo or the, the data protection provider that folks can look for is. It was Yahoo so focused on cogs and they just like, were just. Was it. The data protection was like, hey, there's just too much. You know, we should have looked at the product more and looked at how much customization is needed. Was there any signals that, that you now are like, okay, you know, Yahoo, like if I come m across the bed, just like really focus on cogs. Avoid that. Is there. Yeah. Anything, any lessons there?
Speaker B: Yeah, absolutely. And for Yahoo, the big lesson was we need a standardized SDK. And, uh, going forward, that's all we're selling. So we don't care who you are. You're getting the standard SDK, no matter how big and how much money you want to pay us. It's, it's Model T. It's one size fits all. It's black. That's all we got. You ask for red, we're giving you black. And that's, that's, that's just a cardinal rule that you absolutely have to stick to. Because if, you know, if they ask to change the paint, don't do it. That doesn't preclude doing sort uh, of a white label deal. If you are set up for white labeling. If your product is easily supporting white label, great. But otherwise, um, just standard SDK, standard APIs, to quote or possibly misquote, Donald Rumsfeld. You go to war with the army you have, don't try to invent a new army once you've started the war. And that's certainly, again, guidance for oem.
Speaker A: Fascinating. Real quick, a white label versus oem. How would you classify those difference. Any, any expertise on that? Cause I'm, I'm still learning and I'd be curious your thoughts on that real quick.
Speaker B: Yeah, and I kind of glossed over that. So. So white label is generally considered OEM.
Speaker A: Okay.
Speaker B: But it's a particular kind of OEM because you are taking your, you are providing 100% of the value. Right. If somebody is white labeling your product, they're getting your product as is. It's the entire solution. It's just, you know, rebranded badge engineering if you like. So that's fine. But you know, uh, not every product is suited to that. So if you have a desktop application, maybe that's great, you can easily reskin it and that fantastic. But the road to hell is paved with having to come up with custom builds, custom white label builds for a particular prospect, as opposed to, if you already have all that capability in the back end of your product to essentially hit a button and say, give me those two different builds, one for me, one for my white label customer, then great. But if you can't do that, it's going to be an unhappy experience for everyone.
Speaker A: Thanks for sharing, Chad. That's great. Well, let's, uh, finish up. Let's wrap up with one last question around. What are some of those stories that you. That was like an. It was an unlock, right? We're like, oh, when I achieved this, it was like, oh, I just. You saw the value in the OEM partnerships and what were those? What happened? Once again, you feel free to drop names if you want or not. Maybe one of the most successful OEM partnerships you've had. Uh, yeah, if you have a story around that, that'd be great.
Speaker B: Yeah. So I thought of a third one which is, uh, you know, sort of, sort of a, um, cautionary tale, but, you know, which also had a positive corollary. So another company I was, I was working for, uh, well, again, I came in and, you know, 25% of the revenue, and we didn't have a lot of revenue, so I'm really not talking a huge number, but over 25% of the revenue was generated by a single OEM. And I come in and pretty much simultaneously, hopefully not because of me, the OEM announces, you know what, we're just winding this down. We're not going to renew anymore. Poof, there goes 25% of our revenues. Huge heartburn. And coming back to, uh, one of the issues with VCs, that's obviously a big red flag, uh, with the VCs, fantastic if you have OEMs. But you really want to make sure that no single OEM is going to be more than 10%, ideally no more than 5% of your overall revenue, because otherwise you're just simply too dependent, as we were on that one big single oem. So I had to scramble and I had to fill that hole in our revenue because, you know, we, we had some funding, but not, not massive amounts. I was successful and I was able to fill that hole with, with several different OEMs, several of whom, um, you know, are great customers. They're still OEMs to this day. And again, they, they, they really all felt that filled that criteria of they themselves were selling into enterprises, you know, not really consumer SMB focused, um, very technically savvy, uh, you know, it was just the right Goldilocks mix of the amount of value we were adding to their own solutions. So those were definitely some, some good wins that we got out of that. But that over dependence is definitely another thing I would be, be very careful of. But it's a tricky one, right? Somebody comes to you and says, you know, I'm going to give you a seven figure check every year and you're struggling to make payroll. Man, that sounds good, but it can really come back to bite you.
Speaker A: Thanks, Chad. Yeah, I think there was one. In your early stage, it's hard to say no to revenue, so no matter what form it comes in. Is there any final stories, any, any final takeaways that we haven't touched on or anything, uh, success stories or ingredients or cautionary tales that you'd like to share before we wrap up here?
Speaker B: Yeah, I think that was really the highlights. Um, of course it can be really tempting to engage with the big guys, you know, the Magnificent Seven, as they're called now. I keep wanting to say fangs, but you know, we've moved on from that. So, um, but the Magnificent Seven and maybe the seven or ten adjacent to them. Uh, but you always have to be careful. You know, they know they have the big st, especially with a small startup. So you just have to really hold your ground sometimes with them. And because otherwise, you know, they have teams of people for everything, right? They have layers of PMs, PMMs, directors, uh, of engineering, all kinds of people. And sometimes you have to engage with so many different people, so many different groups, so many stakeholders, uh, might be a fantastic deal at the end of it, but, you know, if there's only just one or two of you, you know, again, that's, that's going to be a very, very draining, uh, sales cycle. So you just want to approach those with caution.
Speaker A: That's a good advice. I love that. Well, Chad, thank you so much for joining me. This is super fascinating. I learned a ton. Where can folks connect with you?
Speaker B: LinkedIn. I think I'm the only Chad Lovin on LinkedIn. Pretty sure. So there's very few Lovins at all in fact. So just do that and more than happy to carry on the conversation.
Speaker A: Perfect, Chad, thanks so much. I'll make sure to put your information in the description. And, uh, thank you all for listening to the Cyber Security Partnership show. We'll catch you next time. Thanks again, Chad, for coming on and thank you, Taylor. Take care.
Speaker B: Appreciate it.
Speaker A: Bye bye.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.