The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Security Podcast of Silicon Valley
The Security Podcast of Silicon Valley artwork

98. How Browser Security Became the New Battleground for Enterprise AI

The Security Podcast of Silicon Valley · 2026-06-30 · 42 min

0:00--:--

Key moments - from our scoring

Substance score

46 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality9 / 20
Guest Caliber12 / 20
Specificity & Evidence10 / 20
Conversational Craft6 / 20

Browser security is no longer a niche concern - it's become the frontline defense for enterprises navigating AI adoption. Orr Eshed, co-founder and CEO of LayerX Security, explains why his company positioned itself at this intersection five years ago, before the category exploded. LayerX provides browser-based security through enterprise-grade extensions that operate agentless in the application layer, giving CISOs control over web, SaaS, and AI interactions without architectural changes. The company's advantage lies in early recognition that users now live outside the corporate perimeter; traditional firewall-based security cannot protect activity happening in browsers and cloud applications. Eshed draws on his background in military cybersecurity, Checkpoint's browser security work, and financial services incident response to frame why this matters. The shift from operating system-centric security to SaaS-centric security - accelerated by Microsoft's deprecation of Internet Explorer and Office 365's cloud adoption - created the technological and market conditions for LayerX's approach. The conversation covers go-to-market strategy (selling to pain points rather than pushing features), founder dynamics with co-founder David, investor selection (Glilote Capital as a vertical cybersecurity VC), and why maintaining focus on a specific ICP matters in a crowded security landscape where 80% of budgets flow to hyperscalers and GSIs.

Key takeaways

  • →Browser security became viable as a standalone category when Internet Explorer was deprecated and Office 365 moved to cloud, shifting security from OS-centric to application-centric - timing Eshed recognized and acted on five years ago.
  • →LayerX's 99% logo retention and organic growth through customer referrals suggest the product-market fit and customer value needed to compete in a market where 80% of cybersecurity budgets go to hyperscalers and GSIs.
  • →Founders should focus on solving proven pain points today rather than pushing entire visions; wedging into qualified demand builds trust and customer relationships that enable future expansion.
  • →Vertical cybersecurity VCs like Glilote provide signal-filtering value beyond capital - they understand buyer psychology, market cycles, and help startups avoid the noise (e.g., 'everyone is doing AI, let's do AI').
  • →Browser extension sandboxing and management became an immediate CISO priority after the Cyber Haven breach, showing how external events can validate product positioning and drive inbound demand.

In this episode

  1. 1Introduction to LayerX Security and Browser-Based Enterprise AI Protection
  2. 2Orr Eshed's Background: From IDF Cybersecurity to Browser Security Pioneer
  3. 3The Evolution of Browser Security and the CyberHaven Breach Watershed Moment
  4. 4Go-to-Market Strategy: Selling to Engineers and Building Customer Advocacy
  5. 5Founder Partnership and Building Trust Through Shared Military Service
  6. 6Customer Success Metrics: Logo Retention and Net Revenue Retention
  7. 7Venture Funding Strategy and the Value of Vertical Cybersecurity VCs
  8. 8Building a Differentiated Business in a Crowded Cybersecurity Market

Mentioned

LayerX SecurityYSecurityOrr EshedJohn McLaughlinAppleUberMicrosoftRobinhoodBrexCheckpointGlilote Capital PartnersDell Technology Capital

Guests

Orr Eshed

Topics in this episode

Data loss prevention (DLP)LayerX SecurityBrowser extension securityEnterprise AI securitySaaS securityBrowser sandboxingCyber Haven breachChrome Store securityGlilote Capital PartnersCheckpoint

Questions this episode answers

What is LayerX Security and how does it work?

LayerX Security is a browser-based security platform deployed as an agentless enterprise extension that provides data security, identity security, and governance across web, SaaS, and AI applications. It operates at the application layer without requiring architectural changes to existing infrastructure.

Why did Orr Eshed found LayerX when he did?

Eshed recognized two converging trends: Microsoft's deprecation of Internet Explorer making all browsers extension-compatible, and Office 365's cloud adoption eliminating the need for OS-centric security. This made solving 90% of security problems with 10% of the effort possible by embedding security in the browser where users actually work.

How does LayerX approach sales and customer acquisition?

Rather than pushing features or fear-selling, LayerX targets documented pain points (like browser extension malware after the Cyber Haven breach) that CISOs already recognize. Engineers self-qualify through recognizing the solution fits their problem; the company avoids scope creep outside its ICP to maintain traction.

What happened with the Cyber Haven breach and how did it affect LayerX?

A DLP vendor called Cyber Haven was compromised when attackers took over their admin account in the Chrome Store and replaced their extension with malware. This raised enterprise awareness of browser extensions as an offensive vector, validating LayerX's focus and driving demand for browser extension management and sandboxing - a capability LayerX had invested in early.

How much of the cybersecurity market can startups realistically capture?

Roughly 10-20% of the cybersecurity market is accessible to startups after accounting for GSI services (50%), hyperscalers like Microsoft and CrowdStrike (40%), and other large vendors. Not all of that addressable market is in-market each year, so early-stage revenue should be measured in millions, not tens of millions.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

There are a handful of genuinely useful structural observations - the Cyber Haven breach vector, the argument that network security players are becoming glorified VPNs, and the market-size math that leaves only ~10% addressable by startups - but they are buried under extended biographical narrative, generic startup-philosophy riffs, and repeated affirmations that eat significant runtime.

A DLP vendor called Cyber Haven got compromised. The attacker took over their admin account in the Google Chrome store, replacing their browser extension used for DLP with malware.
80% of the budget is going to the GSIs and the hyperscalers, actually very little goes to solve risk

Originality

9 / 20

A few contrarian angles land well - the 'poison pill' framing of trying to be the everywhere-AI-security vendor, and the 'glorified VPNs' destiny of network-security players - but the episode also recycles well-worn startup mantras ('fall in love with the problem,' 'everyone loves to buy, nobody likes to be sold to') without adding meaningful new framing.

if AI will be everywhere, it's a poison pill to try and be the AI security vendor
the network security players are destined to become VPNs, glorified VPNs

Guest Caliber

12 / 20

Orr Eshed is a genuine practitioner - IDF background, led a real browser-hijacker takedown at Checkpoint, built a funded company with named institutional investors and a claimed 99% logo retention - but the interview draws him toward founder-journey storytelling rather than the operational depth his background could support.

I led the takedown of the largest browser hijacker operation in history while I was working at Checkpoint
We were the only AI security contributor in 2025

Specificity & Evidence

10 / 20

The Cyber Haven breach is named and described with real mechanism; investor names, the 99% logo-retention figure, and the Verizon DBIR contribution add texture; but several significant claims - 'largest data lake in the world for browser extension sandboxing,' 'great NRR,' 'best customer success in our space by far' - are asserted without supporting data.

A DLP vendor called Cyber Haven got compromised. The attacker took over their admin account in the Google Chrome store, replacing their browser extension used for DLP with malware.
20% of half, which is pretty much 10% of the cybersecurity market, could be utilized by startups

Conversational Craft

6 / 20

The host defaults almost entirely to softball prompts ('proudest day,' 'most difficult day,' 'what inspired you'), accepts every claim unchallenged, and punctuates responses with repeated affirmations rather than probing follow-ups; no substantive pushback occurs anywhere in the episode.

Wow, so it's like the all-in-one AI and browser security platform.
That's spectacular. Everyone is going after social confirmation

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

security37market19problem19build19browser17founder15cybersecurity15first14eventually14idea14technology13understand13world12space12couple12point11

Episode notes

What if 80% of your security budget is protecting the wrong thing? Or Eshed built LayerX after realizing that firewalls and network tools were blind to exactly where breaches actually happen, in the browser. In this episode, Or breaks down how to build a future-proof security strategy around where employees actually work. Tune in. Or: Security: Sponsored by YSecurity Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle. YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything. Book a free strategy call and we'll tell you exactly where you stand. Book your free call: 30 Min Meeting | YSecurity.io | Cal.com Learn more: YSecurity | On-Demand Cybersecurity Team for Startups - SOC 2 in 5 Months

Full transcript

42 min

Transcribed and scored by The B2B Podcast Index.

Before we jump in, a quick note of who's behind this podcast. Imagine this. You're about to close this massive deal. You've been grinding for it.

You're pumped. And then your customer's legal team decides to make things interesting. What happens if you get hacked? How do you protect your data?

And then your brain just goes blink. That's the nightmare founders deal with all the time. That's actually what YSecurity solves, the sponsor of today's show. They're 40 plus security engineers who've actually done security at Apple, Uber, Microsoft, Robinhood, Brex, and so many more.

And get this, you don't hire them, you rent them. By the hour, no massive salaries, no expensive consultants, just real experts embedded in your company helping you get SOC 2, ISO, HIPAA, whatever it is that you need to close that big deal. Set a monthly cap, know exactly what you're spending, and close the deal. Head to ysecurity.

io slash startups and book your free strategy call. Your first eight hours are free. 40 engineers, one full working day, totally free. Go take it.

ysecurity.io slash startups. Hello, everyone, and welcome to another episode of the Security Podcast in Silicon Valley. I'm your host, John McLaughlin, and I'm joined today with a very special guest, Orr Eshed, the co-founder and CEO of LayerX Security.

Welcome to the show. Thank you for having me, John. It's great to have you. It's great to have you.

So would you like to share with our listeners a little bit about what's LayerX Security? Yeah, sure. So again, thank you for having me. And Lyrics is an interesting concept where we're in a world in which users spend most of their time outside of the corporate perimeter using SaaS applications, AI tools.

And it's pretty much impossible to maintain a traditional perimeter security approach. Lyrics is basically around the vision of going where users are. We provide browser security. Now we expand to AI applications as well.

With the purpose of spending most time where users are, we're adjacent to the SaaS space. when eventually, when you really want to detect interactions and provide interaction security effectively, you need to be really baked into the application where police spend most of their time. The benefit of using Lerics is having a true data security, identity security, and governance across anything users do on web, SaaS, and AI. Wow, so it's like the all-in-one AI and browser security platform.

Something like that, yes. And if I'm a CISO and I'm responsible for the security of a large organization, I have all of these users and we're browsing things and we're outside that perimeter, that domain, that security domain, this is a browser extension that's really geared towards enterprise security and compliance? First of all, what do you get out of it? If you're a CISO, you need to think, what do you get out of it?

What you get out of it is full last mile of security across web, SaaS, and AI. If you want a strategy for safe enablement of AI, there's your way to go. The way it's run, it's agentless. It's working in the application layer we deploy as a browser extension built for enterprises across any browser.

We're now expanding to additional applications as well with a purpose to provide the most fine-brained last mile control. What it means for you as a CISO is you get the benefits you wanted, but you don't make any changes to architecture. I think, you know, there are a million startups out there. I always laugh at that.

You know, in the Fortune 1000, you still got only 1000 CISOs. And the number of startups and security vendors is growing. When 80% of the budget is going to the GSIs and the hyperscalers, hyperscalers, actually very little goes to solve risk. And then there are two questions.

A, which problems are good problems to solve? And I think AI and data are great problems to solve because they're very meeting, they're very much meeting the organization. The other question is what kind of technology can make a big bet? Because unfortunately you won't be able to buy features endlessly.

You need to buy something that can scale and expand to additional use cases. I think that's what makes LARICS very unique because we solve really big problems but you'll see it in an intersection in the organization that can scale to other things. Maybe two years from now, AI will be boring. It will be yesterday's news and everything will be around identity.

Guess what? Identities happen online in the browser as well. So that provides a future-proof technology. Yeah, I really appreciate all of that.

I do see like a future where AI just becomes like the norm. People just expect it will be everywhere. You know? Exactly.

I think identity will always be with us. Yeah. So what inspired you to take this on? Like you've been doing this for a while now.

How long has LayerX been around? More than five years. I felt the need. I'm a former practitioner.

So during my career, I spent a couple of years in the IDF. Many Israeli founders come from military cybersecurity background, and I was working on web security. And it was always clear to me that application intrusion identities and applicatively are the most interesting ones. Then when I left to the market, I led the takedown of the largest browser hijacker operation in history while I was working at Checkpoint.

And at the time, everyone was ransomware, ransomware, ransomware. But for me, it was pretty clear that actually the best place to do both defense and offense is where employees spend their time. And the amount of activity happening in the browser, which is scaling actually a decade ago, it was pretty clear to me that I was working at Checkpoint while using a firewall. and stretching that ineffectively with IPS and IDS signatures to try and catch web traffic if you can just be embedded into the session.

And it was always there, and then it was working for financial services, and I was doing IR, and guess what? Every IR investigation would end it with a user downloading something or browsing somewhere or doing something online, and it just, you know, bugged me. I think the point in time in which it was clear I must do something was when two things happened at the same time. One is that Microsoft deprecated Explorer and all the browsers became supportable browsers in terms of browser extension.

So you actually had a technological path that allows doing that. The second thing is a point in time in which Office 365 became accessible and something you can deploy on SaaS. And suddenly you don't actually need the operating system. The operating system is not very significant.

At that point in time, I was like, okay, you can, in 10% of the effort, solve 90% of the problem and do way more. I must do this. Luckily, it was a good time. You know, the company is doing very well.

I'm very fortunate to have great CISO adoption. And then AI is a huge gift for us because it just landed exactly where we are. So you're at the, you weren't just skating to where the puck was going to be. You were already there.

And the puck just sort of arrived. So it's a good question of, you know, is it luck or is it wisdom? them. I think that the overall understanding that the main trend is that it's easier to deploy and deliver capabilities and services as SaaS.

It's an always true statement. And now you really see that when the AI companies develop their own browsers, which is a discussion we'll probably keep for later. And then when you understand that, you just want to be where the crowd is. It sounds like you have a very strong go-to-market engine supporting your journey and connecting with the CISOs.

And maybe it's part of your background. It's absolutely your credentials. You felt the pain point directly, all of that, you know, puts you in a position to be a thought leader in the space. Right.

But, you know, Galileo Galilei said that the earth was round and when he was too much, you know, ahead of the curve, it's not always great. I think there are two kind of sales. One of them is to the mind. The other one is to the heart.

And within our space, selling to engineers is actually pretty easy because they feel the pain. Actually, I never sold to an engineer. They sell to themselves. They self-qualify and they spot us as a good solution.

We don't actually sell. In that regard, I'm not selling. Strategically, it's a good place to be. And then you have people that are less technical and they say, well, you know what?

Whatever vendor is operating my firewall or SaaS, he said they take care of that. And they are a great company. You are not a great company. You're a startup.

I think I'll go with them. I'll stick to them. Like, what's the worst that can happen? So I think it's also outlining and picturing what raises awareness and what empowers the buyer.

Eventually, cybersecurity is not that significantly different than selling ceviche or falafel. It's just a commodity. It's supposed to be a net positive for the buyer. You're not supposed to stress or fear sell to anyone.

You're supposed to be an instrument they can use to get to their professional and personal goals. With that regard, there is some sort of a tension between the long-term vision to what you do tomorrow morning. If I had a time machine and I would have, you know, had the pleasure to go and talk to myself, back then I would have had the conversation that I would have had with any other founder right now. When you start a company, you have this picture that if everything runs smoothly, once you grow and grow and grow, you can tackle the entire world's problems.

Like I'll start with this and then I do that and that and that and suddenly I'm bigger than Palo Alto. In reality, it doesn't work that way. You see a tall mountain, you need a strategy on how to start the incline. You need to find places to hook to and find areas in which there is demand.

And that's something that I really enjoy in our space. I'll give you an example. A bit over a year ago, there has been a huge breach. A DLP vendor called Cyber Haven got compromised.

The attacker took over their admin account in the Google Chrome store, replacing their browser extension used for DLP with malware. Suddenly it raised awareness to browser extensions as an offensive vector. We put a lot of effort. Actually, we were very fortunate to invest in that early on.

We have a technology partnership with Google. We're now expanding it to other browser vendors. We have the largest data lake in the world for browser extension sandboxing, the most hits. We win every day off on browser extension management.

That's what CISOs want today. They have a qualified plan. They tell me I don't have that. I don't want to convince them they have a problem.

I want to go for the problems they already are convinced they have and then grow with them and build the right relationship. So in my vision, once I'm a unicorn, I'm already there with them and they're on my side so we can grow together. So it always a tension between how do you go for your vision all in on your dream or do you go for what people are willing to pay tomorrow morning And I actually leaning towards the latter because if you do that that an enabler to go and fulfill your dreams and everything Well, I think it's fair to say like founders dream.

Yes, they dream of like a changed, a better future, you know, a changed world. And the path to get there, you know, is not a straight line, I think is what you're pointing out. Like you have to have wedges into the market. You have to break into, you know, you have to use a small amount of resources to solve that pain point today.

And then when you actually have that pain point in your crosshairs and it's solved, it sells itself, right? It's not the sort of thing that you have to push. It's not the sort of thing that you have to push hard, right? And this is your experience, right?

People don't want to be sold to. Everyone loves to buy. If I have, you know, 10 minutes and, you know, I'm busy, I guess you're busier than me. If I have 10 minutes to scroll through Amazon and find, you know, a cute coat from my dog, even though he likes the cold winter in New Jersey, I'll enjoy that.

I enjoy buying. I enjoy shopping. Who doesn't? But no one likes to be sold to.

No one likes the experience that they are being sold to. So I think just understanding where the market goes to and being there is just a huge enabler for like, actually, you know, what, you can't bet someone will buy you. So the one true thing you're supposed to do is build a good business. And build a good business that could mean to be a good business over time.

And I think just understanding what drives it is significant. Nowadays, browser security is considered a very hot category with M&As and other stuff and companies going in. And still, we have the best tech. And it's amazing.

Five years ago, not all conversations I had were the same conversations. So obviously, there were the more technical CISO saying, I understand why I need this. I understand where it goes. It's hard to justify a budget.

Let's work on this together. And there were a bunch of people saying, well, look, I don't understand what it is. I can't get it. So it takes time.

The market maturity takes time. You want to enjoy on the bell curve. You have like the time before the slow. You want to enjoy the early adopters and pick the right ones to grow with them, become powerful with them so you can grow better later on.

Because eventually there are always, you know, negative surprises down the road. And sales, you know, sales cures everything. It does. I mean, when the company is growing and the sales are coming in, like, everyone's happy, right?

Definitely. And you're a co-founder, so you have someone that you're building the business with. I'm a co-founder, David, and I actually served together during a military service. Actually, we had the same relationship back then when I was the one identifying whatever we want to build.

And David was run on technology operations, which is engineering, tech operations, maintenance, research, everything. So it was like a glove to a hand. And also we're both very passionate for security. So I actually remember sitting during the pandemic, sitting in a cafe outside because of the lockdown, saying like, look, this is what I want to build.

I'm very passionate about that. Looking backwards, every idea seems like a great idea. But at the point you're done when you launch, every idea seems like a bad idea. Even Facebook, even Google, everything seems like a bad idea at the time when it actually happens.

Looking backwards, everything seems great. And David said, okay, I understand the technical need. I understand the technological need. He said about himself that he envisioned himself being successful, being a CTO of such a company.

I was very fortunate because everything good that we have is due to great technology. Now, I'm not a famous founder. It's my first startup. And we got two amazing outcomes.

It's all thanks to great technology and great products. Yeah, and congratulations on all the success. It sounds like you met your founder and you guys bonded and there's a deep seed of like trust at the center of all of that. I can't imagine you would serve with someone and not trust them.

You have to trust those people that are right there with you. After spending, you know, white nights in which, you know, the lights doesn't go off and you do, you know, some sort of an operation or you have some sort of a catastrophe to handle. You see people performing under pressure. And once that happens, you know how they will behave, you know, under pressure that trust exists in today's world.

So it's great to have a founder you can trust. Whenever I hear about a startup in which, you know, there is some sort of a founder's conflict and something like, yeah, I should have picked a different founder. Like, holy, holy, like, it's like marriage. It's actually bigger than marriage.

Like, you just pick someone from the street and start a startup with. It doesn't work that we need to really, really trust the other person. Yes. Yeah, that has to be there.

That foundation has to be there. That's why it's kind of an interesting thing to hear about how people have met their co-founders and what do they do before, you know, in the previous life to get to where they are today, which is like building amazing companies together. So, yeah. What's been your proudest day as an entrepreneur?

You mentioned this is your first startup. So congratulations on all the success there. You've been at it for a long time now. So you have probably a lot of options to choose from.

The proudest moments I have as a founder, I'm a very, I wouldn't say superstitious, but like you can't celebrate half a marathon out of a marathon. Like you need to get to a milestone and then, you know, wrap it up and summarize. So what's actually something that, you know, gives me leisure? Crossing your numbers, that's tactical.

It's not something strategic. The two things are actually related to our customers. One is a logo retention rate of 99% and great NRR. Like customers sell to themselves, which is amazing.

The other one, when they get an inbound and someone says, that guy who is your customer spoke so highly of you, I had to take a look. Even though I never heard of you, I must take a look. A customer testimonial is worth a thousand efforts I can do indirectly. in other frontiers to get traction.

So whenever I see a customer selling me, they always sell me better than I do. And that's what makes me really proud. It means that I really managed to empower them and strategically grow them. I even have a former workplace that was a customer.

And knowing that they managed to build a technology that moved the needle for them, for pains that I saw when I was there, for me, it's amazing. That's spectacular. Everyone is going after social confirmation, like, hey, what's your NPS score? your NPS score must be through the roof, not promoter score.

I hope so. Oh, I'm sure it sounds like it is. Referrals, I think they speak the most to a company and what's going on. Because in order to leave such a positive mark, you really have to not just get it right, but you have to surprise and delight along that journey to be so memorable.

And it goes to what actually sales means, which is real qualification of the positive outcome for a customer to have your product or services and what would be the negative implication of not having it. The true qualification means that you improve their life. You don't get money from them. They enjoy a service from you.

And when you do that continuously and you manage to scale it, that shows that you're ready for scale and you have the right machine. So it's kind of like qualitative indicators when a customer is so happy with your solution, they are selling it to someone else. It's kind of the proof is in the pudding. I'm curious, you mentioned scale.

Did you take VC money? Yes, of course, you must. So we had actually a small pre-seed investment and two months afterwards, we closed our seed funding. So in mathematical frame, the pre-seed money was at poor valuation because we just raised two months afterwards.

But it's always the case. Our seed founder is Glilote Capital Partners, together with the angels from the cybersecurity industry. Day around was also led by Glilote, together with Dell Technology Capital, later joined by Jump Capital. Glilote is probably the first vertical cybersecurity PC in the world.

They have a great record. The thing I really enjoyed, and I really enjoy working with them, I actually had, it's not that I was lacking options, I'll put it this way, And if I was only looking for valuation and whatever, it's not like I was out of options. The one thing Glilotte offered that others wouldn't offer at the time in which we raised, true deep understanding of cybersecurity market. And it's critical because for every company, things will change.

Technology cycles are so short. You need a partner that really understands the buyer mindset. I think with Glilotte and also my investors that came from Dell and from Jump that are really specialized in cybersecurity, we share the same vision. Sometimes even get things before I do.

They are obsessed with understanding the buyer's mindset. I was privileged many times to get signals coming in from them because the world is so noisy. You know, the world is super noisy. You want to build a business.

You try to understand what kind of signals to process. And, you know, how do you understand? And, you know, eventually as a startup, the only very small subset of the market is exposed to you. You know, half of the cybersecurity market is GSIs.

That's untouched. 80% is the hyperscale. It's Microsoft, CrowdStrike, Palo Alto 14, and a few others. That's untouched.

Like 20% of half, which is pretty much 10% of the cybersecurity market, could be utilized by startups. And not all of it is moving yearly. So not everyone in your ICP is in market. So actually, on the first couple of years, you're supposed to get a couple of millions.

And then you're a great company, not tens of millions, not hundreds of millions. And understanding what's my ICP? How do I reach my ICP? How do I make sure that I don't leak or have a scope creep to outside my ICP and lose traction?

That's great. That's important. And then when your investors don't understand cybersecurity, you can get better advice, such as everyone is doing AI, let's do whatever AI. And I've seen so many companies fail that way.

You need to have someone that you have confidence to fight the world with and swim against the stream And it hard because when you swim against the stream most signals say that you wrong but those are the best possible investments So you need to understand how to filter out the noise And that what you get from great investors Amazing. And as a founder, as a great founder, like you have to be able to see that vision. You have to be able to share that vision confidently, even though it feels like you're swimming upstream, even though you believe something is wrong and can be improved and is different about the world.

If you're at consensus, you're not doing something right. Consensus is really bad in entrepreneurship. Being entirely against everyone is also not the greatest. So you need to really be the hypothesis on the market by finding signals that validate it.

And the vertical cybersecurity VCs, they talk to CISOs daily. They have on their radar everything. They know things before you know them on your space. And eventually it's a force multiplier that's unbeaten.

And you can actually use that vision and that passion and that drive when you share it with others. You're not just sharing it with the VCs and the customers, but you can use it to attract an amazing team that shares that vision and wants to be part of that journey too, right? Exactly. So let's say you have a great idea.

Let's say you have an idea, John, you came up with an idea for a time machine. That's a great idea. Not that easy to build. No, very difficult to build a time machine, yes.

People assume in early stage it ends with your idea. Then you get to execution. And then you get to build the product. Then there are always nasty surprises when you do that.

Let's say you get the product. You get the first couple of sales. You now need to show great self-sufficiency, low CAC, high ACV. You need to build the sales organization.

Good sellers for early stage are like unicorns. If you find one, catch it. And then they ask themselves, why should I go with this company? and they will ask themselves who invested in them.

Do I think whoever invested in them's voice means something that's one? Second thing, they'll ask how much skin in the game do they have? You know, one of the reasons I moved to the U.S.

was because of that. I wanted to show my sellers I have skin in the game and whenever they asked me to join them on a meeting, day and night, 24-7, I'll be there because they need this confidence. If you make good sellers want to work for you, any seller would want to work for you and then you become a good company to be in and that's actually when the race actually begins. It doesn't end at that point.

It only begins at that point. It begins. It begins. Yeah.

It's almost like every day for an entrepreneur, that morning, it begins again. Right. 100%. And you dream about it at night.

Yes. It is. You live and breathe it. What's been your most difficult day along your entrepreneurial journey?

The most difficult day? I was assumed, by the way, I don't know, it's kind of sounds depressed. I was assumed that today is ahead of me. Like I always believe, you know, just try to avoid a day.

Like, I mean, like probably it can always get worse. I think that, you know, you take decisions. Not all of them are perfect. I think the ones, the bad days are those that you fail.

But looking backwards, you had enough information to take a different decision. When you fail, when you had enough information, let's say you miss a huge deal on points, on inches. that's so annoying but you've done the best you could and then if you just put in the meat grinder like 10 of those you'll close five and that's a great company so don't think about that one think about the next one however when when you get into a reality in which you actually had enough information to take a different decision and you went consciously to the wrong path i think those are the places in which i feel really bad because i feel first of all like i burn i burn cash for no good reason like i waste other people's time but also it makes me question my own decision making process and that's when you know i have small depression luckily it happens very rarely on the other hand you know um federer the tennis player was on a vc event one said that he you know he only wins like a bit over half of the matches but he wins those that that matter so eventually became number one you don't have to catch every ball but you need to catch the balls that matter the most so you also need to understand that like where it's good to be depressed and where you know just keep on, move on, because it's never perfect.

It's never perfect. No, no, it never is. You know, focusing on the pieces that matter and being able to discern those pieces, that's critical for a lot of the success for a lot of the game. Yeah.

I'm curious, when you look into the future and you see Layer X security as a smashing success, as it continues to grow, what does that future really look like? Yeah, so the question is, like are you invested in a problem space? We basically invest in problems. We don't invest in solutions.

We invest in problems. Is the problem space I'm investing in, is it a growing problem space or not? Every reality can be good and beneficial for someone and be bad for someone else. Global warming, I guess there is an ice cream shop that's cheering out there.

You need to really be conscious of how you interpret the reality. And when I look into that, I see a couple of trends. One of them is consolidation, which means, pardon my French, that every big hyperscaler becomes like Walmart. You can't really find what you need.

It doesn't really work. Eventually, the impact, the ROI, is becoming very questionable. And with some of those hyperscalers, customers say, I get for cheap a lot of bad products. So we'll see a couple more of those, more hyperscalers and more hyperscaler dollars.

The problem space is becoming to shift more and more. So the understanding that you can't secure everything will be a part of the status quo. application delivery on our space is becoming more complex, more encryption, more sophistication. So I think the network security players are destined to become VPNs, glorified VPNs.

Sorry for being a bit technical. When I think of all of that, it means that we need to expand out of the browser, but we need to be very, very focused on interaction security. I think there is once in a generation opportunity to build a next generation approach to security services edge that does not require dependent on proxies and inline data centers, no complex infrastructure that really is around the user and around corporate assets. It's possible to do that in a lightweight manner now and be more future proof.

And lyrics of a couple of years from now will be, you know, a billion dollar company selling things outside of browser security, but on the same paradigm, which is device centric user governance and expand to other areas, probably, you know, TLP, network security, zero trust, so on and so forth. What shouldn't be happening is becoming another tiny new Walmart. We're trying to do too many things. Aside from that, we'll see other crazy things happening with non-humans, agents, stuff like that, but it's someone else's problem.

Yeah, I was going to ask you, how do you think AI has shifted the future of the security landscape? But I love that ruthless sense of focus that you have, mentioning it like it's someone else's problem. Eventually you have. otherwise like why should then I tell them to CISOs, I tell them when they ask me what about you know this other problem and then I tell them you know we talk about AI and then you have users to AI which is natural stupidity to artificial intelligence sort of thing and then you have agents roaming the web or your customers towards AI and that's an application security problem, it's a bit different, you can try and do everything but then you know I tell them you know the same cow looks very different to the butcher and the veterinarian like you can't assume that everything AI should be handled by the same vendor.

Eventually, if AI will be everywhere, it's a poison pill to try and be the AI security vendor. Because if AI is everywhere, you have to be the everywhere security vendor. Newsflash, we're in 2026, 40 years after the first security vendors came to the market, some offerings are like 30, 35 years old and are actually downsizing. They're starting to minimize what they do.

None of them tries to do everything everywhere. so you can't be everything for everyone. You need to just be in love with an amazing problem that's growing. So we've taken the user-to-AI interaction.

As long as you have employees, you'll have the same mistakes happening time and time again and we can be the strategy that you can go to battle with. And then there should be other companies that take care of the robotic part, the AI part of the business, which is agents. And you have great companies out there. I have no doubt that you'll see some of those specialized vendors doing amazingly well.

And actually, the all-in-one, we do AI here, there, everywhere. Those failing because they won't be able to keep up with competition. And eventually, the world will be more specialized. Another thing is with AI, you can ship quality products faster.

It takes a mind shift to do that. Two mind shifts, actually. One of them is understanding that buyers are not impressed by the quality of your algorithm. So like a decade ago, if you had like, we have the best detection engine for, we have like 140% true positive rate, all kinds of BS that no one believes in.

Nowadays, it doesn't interest anyone. You can take a naive model and do a good enough job. They look for impact and they look for intuitive added value. What kind of data do you process?

Where are you, what kind of context do you have? on that range when you develop your own solution take a step backwards do i actually need a dashboard or can i just have a prompt when you can ask it you know show me trends over the last five days actually you can deploy solutions much much faster more reliable and that's where the world is going the faster you understand how to build with ai the more likely you are to survive So not just using AI to build more quickly, but using AI into the products and the services and the solutions that we're building.

When, after, after we fall in love with the problem. Exactly. I love that ruthless sense of focus. We're falling in love with problems, not with solutions.

I think that will always keep you, keep everyone like hungry for something better. Right. Because a problem will be there. and it gives us the ability to shift and be dynamic around the what how do we solve it like what are we building what are we doing about the problem Yeah Eventually you need you know cybersecurity market is not gigantic You have two companies over a hundred billion, and then you have a couple in the tens of billions, and then the rest are pretty small.

The cybersecurity market is not that it's big, but it's not a like retailer or finance. It's smaller than that. You can build a name easier, but it's hard to get attention as well because of the fact that it's a small market. Everyone wants to get to the same buyers.

And eventually, if you don't have a path towards being a great business, why bother? Like, you should really start with that. And the way to do that, you won't convince people to love your technology. You can offer them a strategy to solve a problem they really care.

So you need to fall in love with their problem. Once you do that, you'll get the attention and they would want to learn from you and they would want to hear from you. Yeah, I love that. And that goes back to our initial part of our discussion about not being sold to, but buying.

I think like when you feel a pain point, you do look for the Tylenol. But like advertising, advertising like, hey, I'm selling this. Hey, I'm pushing that like by itself doesn't doesn't work so well. Right.

And I think it's the bonding point. A bit modesty as well, because there needs to be trust. There is a chance that the problem is a good problem. and there is a chance that your technology is good, but they don't trust you because you don't have a name.

You're a small startup. There's so many reasons why not to buy from you. You just really need to understand the buyer's decision-making process and build yourself towards that direction so you're more credible, you're more reliable, your technology seems like a good fit, and don't try to preach to them because they hate that. How did you establish yourself as a trusted player?

You broke through that yourself at LayerX. So we've done a couple of things. First of all, we've invested, huge investment in customer success and professional services in the company. Yeah, so the way to do that, we have the best customer success in our space by far.

And we make sure that the smaller or larger customer will get the best possible service because they are our ambassadors to the market. That's the first thing. Second thing, don't lie to prospects. Be candid.

It's better to miss opportunities than to misdeliver. Not everyone would agree, but I think you need to make sure that you're trusted. Exactly. The last thing is the qualification.

I think people appreciate when you do proper qualification around their environment. They do appreciate being asked about what's their tech stack? How do they work on things? Even doing a prior analysis, it shows that you care and you really want to have a conversation.

I think those things help with credibility. Yeah, that's spectacular. I couldn't agree more. Those are all great ways to land your first couple of customers and establish yourself as a trusted player and really good work, like identifying investors that bring, I guess sometimes people call them non-tangibles, but bringing things besides capital to the table, bringing credibility and maybe a couple intros and warm leads and a sense of confidence because they're backing you and they're backing the company and they're backing the idea.

So that helps. So it's interesting in the cybersecurity market, there are quite a lot of CISOs that invest weekly in learning and educating themselves by meeting startups to learn what's going on in the industry. Those are people that if they would open up a consultancy service, they should charge like a couple of thousand dollars an hour. So they spend, in a way, they burn their own cash by taking calls with startups to learn what's going on in the market.

and then they want someone to filter for them what are good ideas. So with the specialized VCs, that's something which is good because those CISOs know that VCs are actually pre-qualifying ideas for them. So they're more likely to get on calls. Yeah, that's spectacular.

It's almost like using like Apple or past experience in a successful startup as a signal to hire an amazing IEC who can help execute and build the vision. it just filters and signal yeah i agree and actually probably in reality it's even more important than i think because everyone is looking for external validation for everything and even your buyers want external validation it's you know what's one of the most yeah you know that when you travel to a foreign country in which you don't speak the language and you want to choose where to eat your lunch and you'll go for the place that has the longest queue of people outside standing outside.

Because if others pick that solution, I should go there as well, even though I'll stand longer in line. And it's worth the wait, too. Exactly. Always is.

Exactly. Always is. Well, you know, we have a lot of entrepreneurs who listen to the show. And this may be a little bit of a leading question, but I'll see maybe what's on your mind in this space.

But if there was just one tool or one service that you wish someone out there with the entrepreneurial spirit, which is latch onto and fall in love with this problem and build an amazing solution around it. And you maybe even would do it yourself, but you just don't have the time right now to do that. Like, does anything come to mind? Listen more than talking and ask questions and listen.

If you listen, you'll get all the information you need because eventually Lyrics could have been a faster company launching earlier if we process feedback better. So one of the most beautiful thing in building something or selling something is objections. Objections are not insulting you. That's what I say to the young entrepreneurs that are listening.

When you get objections, someone is offering to sharpen your knife for you. They highlight what are the vulnerabilities and weaknesses with your idea. The faster you solve those questions or address them, the better and more crisp your idea will be and eventually your company will be as well. So once you process that, just listen, enjoy, consume feedback.

Make sure that you get the feedback from the right sources. That's the only service you need. You can get anywhere. Just get to a company that you think you can learn from someone, stand outside, bump into someone on the street.

Like it's actually pretty easy to do that. You just need the courage and you need to be willing to listen. Yep. Yep.

That growth mindset. To not throw up defenses and defend like the idea, but actually like listen to what they're saying and, you know, be open and minded about maybe being wrong about something. Right. So just a little bit.

It's amazing to find that you're wrong. It's an amazing experience. I love being wrong because you're you're learning and you're growing. Yeah.

As uncomfortable as that might be. That's where that comes from. I always tell my employees, you know, if you prove me wrong, the faster you do, you gave me back time, which is the one resource I have very limited. The faster I find out I'm wrong, the better it is for me.

And I, you know, I learned to be in love with being wrong. I wasn't always like that. But after you get spanked by reality once or twice, understanding is not always your hypotheses are perfect. You learn, man, if I only learned I was wrong earlier and faster, it could have been great.

Yeah. When you learn how to do that, you just become a better entrepreneur. You get to. You don't have to.

You get to. Yes. Yeah, exactly. Wow.

That's very profound. That's very deep. I really appreciate you coming on the show and sharing your experiences, your journey, all of the moments along the way. LayerX will have lots of information about everything that we discussed.

Would you like to have any shameless plugs? So if you're in cybersecurity market and what you do is network and endpoint security, you care about what your employees do online, that's the best strategy to go. We have the most robust technology that can get you anywhere you want to be. If you are a cybersecurity practitioner, we're constantly hiring great technicians and non-technicians in the U.

S. as we scale the business. If you're just interested to learn, follow lyrics. We're expecting quite a few announcements on our support and integration into AI browsers, which is becoming a really hot topic in 2026.

And we're always happy to share information. By the way, we're contributors to a lot of research entities, Verizon's data breach investigation reports. We were the only AI security contributor in 2025. And we are always happy to be part of the ecosystem and share information.

There we have it, everyone. The co-founder and CEO of LayerX. Or, thank you so much for joining. Thank you so much for sharing all of this insight, friendly discussion around not just security, but what it means and feels like to be an entrepreneur as well.

We'll have all of the links in the show description. And thank you to all of our listeners for tuning into another episode of the Security Podcast of Silicon Valley. Thank you very much, Ron. One last thing before you go.

Think about who you were 20 minutes ago. Maybe security's been that thing that's on your roadmap, that thing that you'll get to right after the next sprint, the thing that you'll get to after the raise or after something. But here's the truth. SOC 2 and ISO, these things are not just checkbox.

They're keys. It unlocks enterprise deals. It opens up regulated industries. It's the difference between selling to a 10-person startup and closing Fortune 500s.

That's where wide security comes in. We don't just advise, we build. SOC 2, ISO, done right the first time, 40 plus engineers from Apple, Uber, Microsoft, Robinhood, Brex. This is not guesswork for us.

This is all we do. And maybe you're not the one who needs this, but you know a founder who does. The one trying to break into bigger markets. The one doing the zero to one thing.

Send them our way. We have an awesome referral program. We pay for introductions that turn into partnerships. So head to wisecurity.

io slash startups. The first eight hours are free. 40 engineers, one full working day entirely on us. Wise Security has your back.

See you in the next episode.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • When AI Stops Assisting And Starts ActingAI Proving Ground Podcast · on Enterprise AI security90 / 100
  • AI Security: Gerald Auger on Shadow AI, Non Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Data loss prevention (DLP)84 / 100
  • The Role of AI in Cybersecurity: Advantages, Risks, and Future Trends, with Ian PatersonThe Cyber Insider · on Data loss prevention (DLP)82 / 100
  • Episode 56: Dimitri Sirota of BigIDEnterprise Ready · on Data loss prevention (DLP)81 / 100
  • Ep. 5: Food and Agriculture featuring Jonathan Braley, director of the Food and Ag-ISACThe Security Detail · on Data loss prevention (DLP)78 / 100
  • Exploring Zero Trust Networking in a Multi-Cloud EnvironmentBeyond the Screen · on Data loss prevention (DLP)71 / 100

More from The Security Podcast of Silicon Valley

All episodes →
  • 97. The God-Level Hacker: How One Founder Is Building the World's Most Powerful Offensive Cyber Tool (with Alexis Lingad)
  • 96. They Don't Need to Hack You Now. They Just Need to Wait. (with Kevin Kane)
  • 95. Stop Saying No: How Security Leaders Enable AI Instead of Blocking It (with Pranava Adduri and George Gerchow)
  • 94. How one unsecured printer can take down 11,000 devices (with Jim LaRoe, Symphion, Inc.)
  • 93. The Conversation Nobody’s Having About AI (with Jacob Andra and Stephen Karafiath)
Explore the best B2B Engineering & DevTools podcasts →
All The Security Podcast of Silicon Valley episodes →