Gili Raanan - 网络安全投资打法 - [Invest Like the Best, EP416]
- Raanan 认为,网络安全正处于一场“完美风暴”中:地缘冲突已将进攻性网络能力变成战略武器,国家能力持续向犯罪分子转移,而 AI 能以前所未有的速度和规模执行攻击。 这场升级路径从分析延伸至人类增强、工作流自动化,最终走向自主控制。一个 AI agent 可以同时生成并发起数千次基础设施攻击:“这不是未来,而是今天。”
- AI 不只是提升网络安全,而是“将重新定义网络安全”,迫使现有厂商转向 AI-first 和 AI-native。 同一个模型既能帮助防守方识别银行漏洞,也能设计攻击该银行的方案;DeepSeek 等开源系统则拆除了围墙花园。对 Wiz、Cyera、Island 等平台而言,AI 要求重构产品,而不是再增加一个功能。
- Cyberstarts 的业绩支持一套被极度简化的种子期投资逻辑:先挑选非凡的运动员,再帮他们找到紧迫的客户问题。 其首支5000万美元基金领投了9支尚处于想法阶段的团队;Raanan 称,3年内投资组合价值超过250亿美元,5000万美元已接近20亿美元,并孕育出 Wiz、Island 和 Fireblocks。如今 Cyberstarts 管理着5支基金、超过7亿美元资产,据称其中4支活跃基金的 IRR 均超过100%。
- Raanan 看重经受逆境的能力,胜过纯粹的智商,因为“创业是一段极其痛苦的旅程”。 Fireblocks 是这场下注的缩影:Cyberstarts 于2018年6月投资300万美元,随后公司最初10家设计合作伙伴中有6家在加密寒冬中破产;创始人 Michael Chodorow 的移民经历、无父成长和长期不确定性,帮助他重建了计划。面试的关键问题不是一个人完成过什么,而是他为什么做出每个关键选择。
- Sunrise 方法颠倒了传统产品开发流程:先调查痛点,创始人获准写代码之前不许动手开发。 团队会访谈几十位 CISO,追问“你最讨厌的供应商是谁?”,并用真实支出或替代方案行为验证说法。他们会告诉客户,一支新团队将在3年内投入约1亿美元做工程,然后问客户愿意把其中1000万美元的努力放到账外、用来解决哪个问题;之后可能等6个月才开始开发:“这是你最后一次选择正确问题的机会。”
- Wiz 最清楚地证明了:紧迫性、买方简洁性和企业级定价,可以压倒看似高昂的初始估值。 放弃一个重要但不紧迫的安全接入项目后,Wiz 找到了云安全产品:一名 CISO 同时掌握痛点、预算、决策权和部署所需凭证。它拒绝以 PLG 服务大型企业合同,前4个销售季度的 ARR 依次达到约100万美元、200万美元、800万美元和2500万美元。
- 网络安全不是一个可以测绘的固定市场,而是“始终由其他事物衍生而来”,因此 Raanan 更关注人才和流程,而不是预测品类。 他认为,只要市场足够大、痛点持续变化、人才到位并加上一点运气,一家新的网络安全公司可能在10年内超过 Wiz 在有条件假设下5年从0达到320亿美元的成绩。他更深层的建议是,把投资当成一个“人生项目”,对创始人有真实关切,而不只是追求盈利。
1. AI 让网络安全进入机器速度的冲突
2018年,网络安全看起来仍只是“IT 中无聊的一部分”;如今,Raanan 认为全球冲突正把进攻性网络能力变成致命武器或战略武器。国家能力不断向犯罪组织、最终甚至“脚本小子”手中转移,令整体安全基线明显恶化。
他的战争类比从更好的分析,推进到人类增强、工作流自动化,最终走向 AI 控制。增强暂时“可能已经够用”,但防守方最终需要由 LLM 预测攻击,并由 AI agent 及时响应。他认为,终结者式的未来“今天已经成为现实”。
进攻策略仍由 ROI 驱动:用最少的时间、精力和成本,造成最大的情境性破坏。Raanan 举的例子是攻击为发电站提供支持的名称服务器,可能让一个国家数日无法获得电力;一个 agent 可以同时生成并执行数千种此类攻击场景。
双重用途不可避免。一个基于银行基础设施训练的模型,既可以建议防御性修复,也可以揭示如何让银行离线,就像药物模型既可能提出疗法,也可能设计毒药。护栏可以被绕过,而 DeepSeek 等开源模型意味着“AI 已不再是围墙花园”。
2. Cyberstarts 把种子期投资还原为选运动员
2018年离开 Sequoia 后,Raanan 得出结论:风投的早期投资模式“彻底坏掉了”。投资人会盘问创始人市场、产品、竞争和定价,但这些答案几周内就会变化,而真正的目标客户根本没有参与讨论。
Cyberstarts 转而评估人,并“寻找他们经历过的逆境”。Raanan 在自家后院的集装箱办公室里起步,用5000万美元基金领投了9支尚无具体想法的团队,并仅凭创始人本身押下了许多观察人士认为异常大胆的赌注。
3年后,他称这9支团队的价值超过250亿美元,最初的5000万美元已接近20亿美元。投资组合包括云安全龙头 Wiz、企业浏览器创始公司 Island、价值80亿美元的加密托管服务商 Fireblocks,以及几家分别以数亿美元被收购的公司。
Raanan 将命中率归因于狭窄的投资逻辑、创始人筛选、Sunrise 对产品市场匹配的追求、坚定的合作伙伴和运气。如今 Cyberstarts 管理着4支种子基金和1支延续基金,总规模超过7亿美元;按他的计算,约450亿美元的投资组合相当于全球私有网络安全市场总市值的50%。
3. 逆境是 Raanan 最信任的创始人信号
高 IQ 有帮助,但 Raanan 最看重的创始人信号是“逆境,以及克服逆境的能力”。创业必然带来痛苦、不确定性和计划破产,因此他希望看到一个人已经承受过重大挫折,却仍然继续前进。
Cyberstarts 于2018年6月向 Fireblocks 注入300万美元。不久后,公司最初10家设计合作伙伴中有6家在加密寒冬中破产,迫使 Michael Chodorow 重新思考客户和计划;Raanan 将这种韧性与 Chodorow 童年移民到以色列、无父成长以及由单亲母亲抚养的经历联系起来。
人生故事只是切入口,因为“故事重要的不是发生了什么,而是为什么发生”。Raanan 会追问职业选择、关系、动机和自认为的超能力;有意思的是,最好的创始人可能并不知道自己真正的天赋,因为那件事对他们而言自然得完全不值得注意。
4. Sunrise 从痛点出发,把代码往后放
Sunrise 源自 Raanan 在1997年的创业失误。Perfecto Technology 的团队做出了他所称的首个可用 CAPTCHA 原型,却找不到商业模式,随后转向 Web 应用防火墙;公司后来更名为 Sanctum,与 Watchfire 合并,最终被 IBM 收购。
这次反转成为方法论的基础:不要先发明技术,再去寻找客户。先识别痛苦的问题,找到有明确付费意愿的买家,然后再构建“普通人能够使用”的产品。
团队会访谈几十位 CISO,但不会只问他们“最大的痛点”,因为答案每周都在变化。更好的问题包括:“你最讨厌的供应商是谁?”更重要的是,“嘴上说说很便宜”:创始人要检查预算、开源试验、顾问搭建的替代方案,以及与供应商的沟通,寻找实际行动的证据。
Cyberstarts 会告诉客户,每支新团队将在3年内投入约1亿美元做工程,然后询问他们愿意把其中1000万美元的努力放到账外、用来解决哪个单一问题。创始人从几十次访谈中选定问题后,还会再进行一轮访谈来设计方案,并可能在写代码前花6个月。后续模拟会假设评估或销售失败,再反向推演产品、定价、渠道、人员配置和总部地点。
5. 资本是燃料,但价格可能削弱利益绑定
Raanan 的融资原则是:“重要的公司通常不便宜。”一旦产品和团队都正确,CEO 的首要任务就是获得足够资本,扩充工程和销售能力;估值必须足以支撑融资,同时不能迫使创始人在 A 轮或 B 轮交出50%的股权。
Cyberstarts 的种子期定价在7年间变化不大:首次创业者通常获得1500万至2000万美元投后估值,连续创业者则从4000万至5000万美元左右起步,并可能进一步上升。
他的判断有明确前提。定价“疯掉”时,Raanan 会放弃投资,因为持股仅5%的投资人可能不会把这家公司当成投资组合优先事项;但 Wiz 进一步证明,顶级公司从种子期起就很贵。“如果有充分理由,高价公司其实是好事,不是坏事。”
只要买方相对同质,Sunrise 就可能迁移到其他行业,例如金融科技、游戏或医疗器械;但 Raanan 还要求行业拥有健康的收购生态,因为并非每家公司都能走到公开市场。此前12个月内,Cyberstarts 已出售5家投资组合公司,累计交易额25亿美元。
6. Wiz 说明紧迫性为何胜过重要性
Wiz 的准备始于公司成立前8年。4位创始人先创办 Adallom,3年后于2015年卖给 Microsoft,又花5年时间将 Microsoft 的云安全业务做到约10亿美元收入;到2020年离开时,Raanan 认为他们已是全球经验最丰富的云安全团队。
他们最初的公司概念 Beyond Networks 面向卫星办公室的安全接入。客户认为问题重要,却不紧迫;而对创业公司而言,紧迫性决定一切,因为它会加快客户投入、学习、迭代和收入增长。团队于是转向自己熟悉的云安全,并将公司更名为 Wiz。
Raanan 的“四角色测试”分别区分:谁感受到痛苦、谁掌握预算、谁拥有采购权限,以及谁使用产品。如果4个角色是4个人,“走人、转向”;2个人可以支撑一家强公司,3个人则处于临界状态。Wiz 是“大满贯”:4个角色全部由 CISO 一人承担。
凭借 AWS 凭证,Wiz 可以在第一次潜在客户通话中展示针对具体客户的价值。随后,它放弃 PLG,转向高价企业级销售,前4个销售季度的 ARR 依次达到约100万美元、200万美元、800万美元和2500万美元。
7. Wiz 的规模仍未让 Raanan 满足
Wiz 将产品市场匹配与异常高效的工程能力叠加起来。联合创始人 Roi Reznik 寻找那些把写代码当作爱好的人——即便周末安静的一小时,也会拿来编程。Raanan 的算术是:100名这样的开发者,可能相当于300或400名优秀工程师,因为顶尖开发者大概是普通优秀开发者的10倍。
Raanan 称 Wiz 是增长最快的独角兽,也是达到1亿美元和5亿美元收入最快的公司,并很可能在当年达到10亿美元 ARR。但即便假设 Google 在5年后以320亿美元估值收购 Wiz,也没有让他满意:“我真希望……能再对那个决定做一次 A/B 测试。”
他预测未来10年内会有人打破这一纪录,可能仍在网络安全领域,因为所需条件依然存在:庞大市场、快速变化的痛点、工程和商业人才、经验丰富的投资人,以及运气。他不预测具体品类——安全总是跟随云、移动、IoT、自动驾驶汽车、AI,或下一个出现的事物。
这种饥渴感与深重的失去并存。在创办 Cyberstarts 之前,Raanan 的19岁女儿去世;他学会“与痛苦共处,而不是对抗痛苦”。与年轻人一起做创新、解决现实问题,也帮助他保持更年轻、更健康。由此延伸出的投资建议是:寻找一份“人生项目”。后来,他的儿子经过思考告诉他:“我是他最好的朋友。”
My guest today is Gili Renan. Gili is the founder of Cyberstarts, a VC firm focused on cybersecurity and the world's first VC firm majority backed by cyber entrepreneurs. Cyberstarts' $50 million first fund exploded to close to $2 billion in just 3 years. Gili describes cybersecurity today as the perfect storm, where global conflicts and AI advancements are creating unprecedented threats. He talks about Cyberstarts' sunrise methodology, which uniquely identifies customer pain points before building solutions.
We discuss a focus on finding resilient talent, overcoming personal adversity, the evolution of the cybersecurity landscape, and Google's recent acquisition of Wiz, where Cyberstarts was one of the earliest investors.
Gili, I've been so excited to do this with you, in part because, in the 500 or so episodes of this, I don't think I've ever talked about the thing you invest in, primarily cybersecurity. And because your personal investing story and life story is so damn interesting, we're going to go all over the place. Maybe you can just give us the very high-level state of the union in cybersecurity today.
1. Cybersecurity Enters A Perfect Storm
Cybersecurity for over 35 years—I'm not happy to admit it, but that's reality—so I believe I do have a perspective on it. We live in days where it's actually the perfect storm in cybersecurity for various reasons. When I look back at the days I founded Cyberstarts, just under 7 years ago, in 2018, it wasn't the case. In 2018, cybersecurity was considered a boring portion of IT.
I think that what we see today is that there's a global power conflict that drives major forces into cybersecurity. It's the Ukrainian conflict, the Gaza conflict. It's all over the world. Offensive cybersecurity became a lethal weapon, or even a strategic weapon, for the states and powerhouses involved in those conflicts. So that's one element that's making the cybersecurity threat vector so real, so dangerous, so available.
And there's a constant drift from state-level cybersecurity weapons to criminal organizations, and then just script kiddies. We live in a very dangerous world, way more dangerous than it was just a few years ago. So that's one. The second element is technology.
2. AI Redefines Cybersecurity
I think that we've seen the iPhone moment for AI in 2023, or maybe even 2024. AI is not going to improve cybersecurity. It's going to redefine it. The same technology, the same LLMs, and the same AI agents that you'd use to predict attacks and prevent them would be used against you to deliver attacks at a scale and level of sophistication we haven't seen before.
The methods that we've developed over the past 80 years, starting in World War II, would be useless because the speed, scale, and sophistication of those attacks would be something that we haven't seen before. The world is a way more dangerous place today. There's lots of risk ahead of us.
I'm curious if you could analogize cybersecurity offense and defense to simple military concepts or something like this. If I think about the evolution of kinetic warfare, from muskets up through nuclear weapons or something, is there some similar escalation of the tools being used by attackers and defenders in cyber? Have the targets changed over time? Have the attackers' goals changed over time? If I were to think about the evolution of the battle, what are the key steps in that evolution?
Think about modern warfare and the use of technology. It started with better analysis and a better decision-making process. Then it moved to human augmentation. Think about the introduction of the first tanks in the First World War or the introduction of the Kalashnikov. It made humans more lethal. But with AI, there are additional steps. It's workflow automation, and then the final step, where AI takes control.
If you think about modern warfare, you think about LLMs that quickly put together attack plans that you didn't practice for, you didn't plan for, and you don't have a Plan B or Plan C for. They're already using AI agents to take control and launch those attacks. On a different side, that means that human augmentation would be an improvement. For the time being, it might be enough, but it won't be a great solution for the long term.
In the long term, you'd have to use LLMs to predict attack vectors in the very same way and give AI agents control, so you have a chance to respond to those attacks in a timely manner. That's the future we're going to. There's no question about it. If you've been a fan of the Arnold Schwarzenegger Terminator movies, that's been a science-fiction future. I think this is reality today.
What does that mean in terms of attack targets? What are the offensive systems, let's say, a bad actor—what are they trying to disable? What are they trying to shut down? What is the primary, most damaging strategy of the attacker today?
The best offensive tactics are always ROI-driven. How do I apply the highest damage to you with the smallest effort, lowest cost, and fastest way? And the damage is always a contextual question; it depends who you are. But we've seen examples of so many different ways to inflict pain on a target, and some of those attacks used very, very simple measures, but the outcome was unbelievable.
Could you give an example?
If you'd like to take a country and put it on its knees, that takes, using conventional methods, a huge amount of resources, time, and coordinated effort by a lot of people. If you do that through cybersecurity, you can use very simple ways, like taking down the nameservers for its power stations, and you leave that country without power for a few days. It's not a highly sophisticated attack.
You don't have to have an army of people doing that, and it can happen to any country any day. Now think about an AI agent that's able to produce thousands of scenarios like that and execute all of them simultaneously. That's the technology today. This is not a future thing. That's today.
What does that mean in literal terms? When you describe it that way, what comes to mind is an agent that can brute-force-create ways in and just try them all. One lands and is successful in its attack. Is that the right way to think about it, or, if that's a shotgun approach, is it more of a rifle approach enabled by the agent in a way that wasn't possible 5 years ago?
The deduction model would always be as good as the data provided. Take the analogy in the drug-development industry. If you provide enough information about a certain disease, you build an LLM that can take that patient data and a lot of research and offer recipes for drugs that can, for instance, heal diseases considered unhealable—let's say, Alzheimer's. You can use the same LLM and ask for recipes for drugs that can kill people. It's the same system, the same method, and the same software.
Now think about an LLM that's fed data about the software infrastructure of a bank and an AI agent that you use to ask questions like, “What are the potential breaches in my infrastructure, and how should I protect myself?” It's a very useful agent. You can ask the same agent directly, or trick it, to answer the question, “How would an attacker breach the defenses of that bank and take that bank offline?”
So the same technologies that we use for the defense are the technologies that would be used on the offense. You've seen that even if you put a lot of guardrails into the model, there are many ways to bypass those guardrails, and that's when AI is in a walled garden. Now you have open-source models, and DeepSeek is just one example of that, where AI is not a walled garden anymore. It's in the wild, and anyone can download the model and modify the model.
If I think about the average lifespan of a cybersecurity company in the state of the world today and over, let's say, the next 20 years, there's that famous chart of the average lifespan of a company in the S&P 500 that's getting shorter and shorter and shorter. Does that line look even crazier and steeper for cybersecurity companies? If the attack and defense vectors are evolving so quickly, how can a company build enduring value?
The answer is fairly straightforward. AI would redefine cybersecurity. It would replace the old ways cybersecurity solutions were architected—the old systems of building rule-based systems and behavior-based systems—so the good guys can fix misconfigurations or patch buggy software systems.
Those days are gone. Founders would have to create cybersecurity companies that are AI-first and AI-native just to have a chance to build lasting, important cybersecurity companies. That's the reason you see existing major players, like our own portfolio companies, putting so much effort into AI. You see the level of effort that major cybersecurity platforms like Wiz, Cyera, and Island put into understanding and learning AI and applying it to their platforms.
That's not an additive capability to the product. That's re-architecting the product to make sure it's useful and effective when the attacker is not human and is not just human-augmented. It's a machine that attacks you.
Can you tell the story of the first fund, which I think will probably go down as one of the most spectacular early-stage investment funds ever? I would love you to share the numbers and the companies and just what happened. It's a sort of thing of legend now, and then I want to build on that for how you've built the business afterward. You started in 2018. The first fund was small. Tell the story of that first fund.
A lot of what happened in that fund relates to a lot of learnings and mistakes I've made earlier in life.
Can you give those?
Oh, yeah.
Touch on some of the major learnings, mistakes, and lessons—the key ingredients that were in place in 2018 from your experience that went into that first investment fund.
3. The First Fund Explodes
In 2018, I had just exited one of the best VCs in the world, Sequoia Capital—an amazing team. I spent a decade as a general partner, and beforehand, I'd been a founder and CEO of 2 software companies. My conclusion back in 2018 was that the venture model was completely broken. It's broken in so many ways. It's broken for investors, and it's broken for entrepreneurs.
Investors have spent an endless amount of time asking about markets, products, and technologies, which founders at a very early stage, at the seed stage, clearly don't have the right answer to. They don't have an idea. Whatever they tell the investor would change within a few weeks, and then change again and change again and change again. Everyone is simply playing a game and dancing the dance, but they're just paying tax to the system. It has no value, especially for the recipient of the solution, because they're not even involved in that dialogue.
When I founded Cyberstarts, I made one very important commitment: to completely avoid questioning the market, the technology, the product, or the competitive advantage, and focus on one thing only, which is the person ahead of me. Focus on the talent. The other thesis I had was hunting for adversity. I'm looking for people who are not straight lines, who didn't have a perfect start in life and managed to overcome it and become successful, although they didn't have a perfect starting point.
I had a very humble beginning for Cyberstarts. I started with a $50 million fund, which was super small. The first fund I was investing alone out of my office was—and still is today—a shipping container I converted into an office situated in my backyard. I invested in 9 teams, and I was the lead investor in all those teams. I made real bets in people without ideas, and many people thought that was pretty crazy. A grown-up writing large checks to people without an idea seemed pretty odd.
Then, 3 years later, in 2021, I realized that the portfolio of those 9 teams was valued at over $25 billion. It had converted the $50 million into close to $2 billion. More importantly, it had a terrific set of companies: companies like Wiz, a decacorn and the leader in cloud security—an amazing team we can talk about a lot; companies like Island, which invented the enterprise-browser space and today is valued at around multiple billions of dollars; and companies like Fireblocks, the largest blockchain custody service for enterprises, which was valued at $8 billion.
As you know, in our business, if you invest early in terrific companies—if you invest early in DoorDash or Airbnb—you'll do disgustingly well. But a hit rate of 4 or 5 unicorns, including 1 decacorn and a few other companies, each of which was acquired for hundreds of millions of dollars, was proof that there was something right about the model and the thesis.
If you think about that outcome and decompose it into a couple of things—a bet on cybersecurity, a bet on these 9 people, a bet on the business models or the way they approached the market, and then some other catch-all bucket—what do you think were the most important contributing factors to that first fund's success and the success that's continued to happen since? The hit rate is crazy. The number of huge outcomes is crazy. Maybe the fourth bucket is luck. How would you break out the reasons for the success?
Luck is definitely important, but on top of luck, I think Warren Buffett once said that as he works harder and harder, he becomes luckier and luckier. So definitely, luck is important. But I think the major factors here are a clear thesis. Cyberstarts is one simple thesis: one sector and a commitment to deliver real value to the founders we partner with.
The clarity of that thesis, and the fact that we focus just on a single sector and own it, are important. So are the founder-selection criteria, and the fact that we made our decision-making process super simple by completely eliminating considerations like market, technology, product, competition, business plan, pricing, and whatever else it is. We do not waste time on those things initially. We spend our time making sure that we bet on the right athletes.
So luck, thesis, founder-selection criteria. Then I would add 2 other factors. One is the commitment we have to get to product-market fit as fast and efficiently as we can. That's the whole story of our Sunrise program. The Sunrise program means that you do not develop technology or solutions in a vacuum, but that you build software solutions that people really need and can use on a daily basis.
I would say the last element is that I'm surrounded by 4 amazing partners. Each of them is adding tons of experience, value, and knowledge, and coming from different backgrounds. I think all those 5 elements make Cyberstarts what it is today.
To continue the story of Cyberstarts, today, with all the humble beginnings we had, we manage more than $700 million under management across 5 funds: 4 seed funds and 1 continuation fund. The portfolio's cumulative value today is around $45 billion, which is 50% of the worldwide market cap of private cybersecurity companies. Fifty percent. That means that we seeded 50% of the worldwide market cap for private companies in cybersecurity, and that's in under 7 years.
Pretty good.
Yes. We believe in cybersecurity. Give us another 7 years, and let's see where we can go from here. Each of the 4 active funds delivered over 100% IRR to investors. So this is not just a case of 1 successful first fund and then living on the success of that fund. I think that we deliver value to founders and limited partners across all the funds systematically.
Let's step through that process, starting with founder traits. You're betting on people, many of whom don't have an actual idea yet, and so you're really just incredibly focused on the quality of the person. What have you learned about what matters? What are you looking for?
4. The Adversity Advantage
My personal experience as a founder and builder taught me that a startup is an insanely painful journey. It's super hard, and like it or not, you're going to face a lot of challenges. That made me believe I shouldn't simply look for the smartest person in the room. High IQ helps. It's not a bad thing, but it's not the most important thing.
The most important thing, in my view, is adversity and the ability to overcome it. For me, this is the greatest signal, the best signal, for a terrific founder. Take, for instance, Fireblocks founder and CEO Michael Chodorow. Let's start with the company so you understand the context. Fireblocks is the leading crypto-asset custody service for enterprises. It's valued at around $8 billion and has thousands of customers, including BNY Mellon, BNP Paribas, and ABN AMRO.
Fireblocks was my first investment in Cyberstarts in 2018. In June 2018, we invested $3 million, and that was the seed investment for Fireblocks. It's an $8 billion company today. Michael's personal story is that he immigrated to Israel from the former Soviet Union as a child. He grew up without a father and was raised by a single mother. He learned early in life to navigate uncertainty: moving to a new country, learning a new language, learning how to deal with things, and pushing through challenges.
I loved it. I thought that was the most important thing. Michael is a friend, and he's a brilliant guy, but I'm sure that there are people out there with a higher IQ. But that's not what's important. When he started the company, just a few months after the first investment, we got into the first crypto winter. 6 of Michael's first 10 design partners went bankrupt.
So how do you deal with that? That's a major blow to your plan. Design partners are so important to building a solution, and he had to simply rethink the entire plan, the focus, and who the customers were. I think that his childhood experience, the roughness in him, and the life experience that you face challenges and manage to overcome them—that's what kept him moving forward, overcoming those challenges, and building an amazing business.
How much of your evaluation of these people is effectively just saying, “Tell me your life story,” and if they literally just answered that question in detail, would it be all you need? If it’s not all you need, what else do you need?
It’s part of what I need. It always goes there, but I learned that what’s important in a story is not the what; it’s the why. It’s not about what you did, it’s about why you did it, why you chose to do that, why you picked job A and not job B, and why you picked that partner in life and not another partner.
It’s always about the why. So it’s not just about a unique, heartbreaking life story. It’s about spending time with an individual and understanding the way they make decisions, the way they analyze a situation, what drives them, and what really makes them tick. It’s not so much about what they did and what accomplishments they managed to achieve. It’s always nice to know that, but that’s not what’s important.
If you think about the next step, you select someone, and they’ve got this personality type that you love. You then go on a hunt for the right problem, and maybe this is just the excuse to talk about the Sunrise methodology that you’ve established. Walk us through that process.
I want to highlight how strange this is relative to the outcome so far. I’m not aware of another early-stage investor that’s this systematic, with this high of a hit rate in such a narrow field. I think spending extra time on the methodology from here would be useful. Let’s just assume you can find great people, which I know is hard, but you’ve got a batch of great people. What was the origin story behind Sunrise? What is it, and how did it come to be?
5. Sunrise Starts With Pain
I think that in order to tell the full story of Sunrise, I have to go back to 1997 and my first startup experience. By that time, I had just finished a decade of service at the Israeli NSA, in Unit 8200. I’ll tell you more about it in a few minutes. The formative years in 8200 were formative years for me, and I got to work with a brilliant set of people.
In many ways, those were the years during which the cybersecurity market in Israel was created. I worked with folks like Shlomo Kremer, who is the founder of Check Point and Cato Networks today, and Gil Shwed, the Check Point CEO and founder, who was just 2 years older than I am. We heard many stories about him. The officer who was sitting next to my office was Nir Zuk from Palo Alto Networks.
Those were the formative days. I left the service and started a company, and we raised money from Sequoia Capital. That was the first time I encountered Sequoia Capital. Pierre Lamond was on my board. We didn’t have a clear idea of what we wanted to build. One of the first technologies we thought about developing the company around was a challenge-response system that would distinguish between a human and a bot or machine.
Years later, I realized that the name for that technology is CAPTCHA. We were lucky to invent CAPTCHA and build the first working prototype of it. I hired two 16-year-old kids. At that point, we weren’t funded enough. I hired two 16-year-old kids. Later, they became Ohad Pressman, who was the CTO of Chegg, and Eyal Navon, who later became the CTO of Hippo Insurance.
Those are 2 very successful companies and 2 very smart individuals, but their first real project in the commercial world was to build the first CAPTCHA. We built the first CAPTCHA, tried as hard as we could, and couldn’t find a business model for the technology. That taught me a lesson, and we had to pivot into something else.
Luckily, we pivoted into the web application firewall space. We were the first team to build a web application firewall. That was the path. That company, Perfecto Technology, which was later renamed Sanctum, managed to build itself. The company later merged with Watchfire and then was acquired by IBM.
But that lesson from CAPTCHA—that you can invent and build a very impactful technology that almost every person on the planet uses, and still be unable to find a business model for the technology—convinced me that I was completely wrong about the way I approached my startup. I started with the technology and then searched for who had a problem that the technology solved.
The process should be reversed—completely reversed. We should first look at the important pain points in the market, find the customers, find who’s willing to spend money on solving that problem, and then go and build a solution that mere mortals can use. That shift in order, as simple as it sounds, is what made Cyberstarts as successful as it is, and that’s what helped all those amazing founders realize the full potential of their talents.
We continue to evolve the Sunrise methodology because it’s not just about product-market fit. It’s actually a program that takes an entrepreneur from day 1, from inception, through the first 3 or 4 years of running their business. But the early days of Sunrise are all about focusing on finding the most important pain point in the market. You do that by going out and speaking with large organizations, making sure you understand their priorities and what gives them the most pain, and only then moving forward.
Can you describe that piece specifically in some detail—the tactical method for who you’re talking to, how many people you talk to, and how often you do it? I think it’s such an interesting process.
Keep in mind that our company is B2B SaaS, so all of them sell to large organizations. Obviously, large organizations are the customers, and they’re who you want to ask the questions. The best person to ask is the chief information security officer who oversees the security operation for that business.
The idea behind the Sunrise process is that you’re going to chase pain and identify pain. That requires a lot of smartness, because if you go out and ask the chief information security officer, “This week, what’s your biggest pain?” you’ll get one answer. You ask the same person the same question in a week, and you’ll get a different answer. Then, another week, you’ll get another answer. They’re not playing games; they’re just being human.
There are other ways to identify pain. For instance, one of my favorite questions is, “Who’s the vendor you hate the most?” If you don’t like a vendor, that’s a big motivation for you to displace that vendor. Another important observation is that words are cheap, so don’t look at what the customer says. Look at what the customer does.
If you’re running security for a large bank, you probably manage budgets of hundreds of millions of dollars. If you claim that there’s one thing inflicting a lot of pain for you, you worry about that. You think that your bank is at risk, and you haven’t done anything about it. It’s probably not as important as you claim.
You’ve probably done something. You downloaded an open-source package to try it out. You went to consultants to develop a temporary solution. You had real conversations with Palo Alto Networks or Wiz to see if they could solve that issue for you. You’ve done something.
So we’re asking them not about their opinions, but about what they actually did to try to deal with that pain point. Eventually, we reverse the power balance in the conversation because we’re not asking for favors. We’re telling those organizations, “Hey, this is a new Cyberstarts team. That new team would spend about $100 million in the next 3 years on engineering alone to build one solution.”
That’s the average for a Cyberstarts company: a $100 million R&D budget for 3 years. “What is the one thing that you care about that you’d like us to solve with our $10 million? You don’t need to spend anything on that. We’re giving you, essentially, $10 million off-balance-sheet to solve one pain point for your organization.”
I found out that when you give people $100 million, virtually, they listen and they think. Then you take those answers, and you’re not having 1 conversation or 2 conversations. To have a statistically meaningful outcome, you need to talk to dozens of organizations. You speak with dozens of organizations, and you make a choice: This is the one pain point I’m going to go after.
Then you do another round of conversations, assuming you’re going after that pain point, and ask them questions about what a solution would look like. You’d really like the solution to be loved by the users. Only then—and sometimes it takes 6 months—do you start to build software.
If you think about the typical startup, when they get money from VCs, they start to get pressure to build software, push forward, and hire people. My approach is almost the opposite: Sit tight. Don’t get too excited. This is your last chance to pick the right problem to go after, so let’s make sure we pick the right one.
The outcome is that they build software that solves a major pain point, is verified with dozens of real customers, and is a solution that people would love because they talked to those people before they started writing code. Now, it doesn’t work with every team, but as I think I’ve demonstrated, the success rate is quite high.
If I back up now and think about the process so far, it’s the identification of these people who have this super-resilient history and DNA. It’s the application of the Sunrise program to start identifying and then ultimately pick a problem that’s super valuable, using this unique set of questions.
What’s the next phase? Are these things built in a distinctive way relative to the normal startup that you’ve observed before, or is it at that point a standard software-building exercise?
It’s a standard software-building exercise, but perfectly done, because you start from the end and work backward. It starts with the end in terms of value: What value would the customer like to produce with that piece of software?
The sales process doesn't end at 6 months. It's a full simulation of everything you are going to face in the next 3 or 4 years as a founder and as a company, and how you deal with it and architect your company to run as fast as feasible in the first 3 or 4 years.
If you demo the product and they don't take you for product evaluation, why is that? If I tell you the man from the future tells you that they evaluated the product and didn't buy it, why is that? We use a lot of simulations that assume failure and force the founders to really analyze the situation, assuming a failure, and build their company to deal with it.
So it's not just about the product. It's about the go-to-market team, pricing, channel strategy, and maybe the location of headquarters. Those are many, many elements that are evaluated and examined during the Sunrise.
One of the things that is incredibly interesting to me is how you must drive a low cost of capital for these companies because of your involvement. I would imagine you've got all sorts of other investors with deep pockets who would desperately love to blindly fund companies that are partnered with you at Seed, at Series A or Series B, or beyond.
How do you help the companies manage their future financing, and how do you think about how aggressive to be on valuation, how much capital you raise, and dilution? This is a really interesting part of what you've built with such a high hit rate.
We think of co-investors at Cyberstarts as partners. I don't take them lightly, and we are fortunate to have amazing co-investors who have repeatedly backed our portfolio companies. We have tons of respect for their contribution and their support of the companies, because Cyberstarts can be as great as we like, but there are other smart, capable, knowledgeable people in the world, and we're happy to get their help.
We are definitely in the early days. We are highly involved in fundraising and helping our companies finance their growth. My approach is that it is expensive to build important companies. Important companies are typically not cheap.
When I hear founders getting advice like, “Keep valuations down. Make sure you don't raise too much money,” my approach is that your first priority as a CEO is to have enough money to build the right product and hire the right sales teams. That's expensive.
So, in order to raise enough money, the valuation should be high as well, because no founder would sell 50% of their company in Series A, or in Series B. I'm all for raising a lot of money, assuming you've built the right product and you have the right team, so you can scale and take on the opportunity.
How do you think about pricing at Seed for yourself? What's the right way to think about this? How much variance is there between the valuation at which you've tended to enter companies? Has that changed a lot since 2018?
It almost didn't change in 7 years. We typically see 2 types of deals. If you like a pricing menu of 2 items, we see 1 market for first-time entrepreneurs—people for whom that company is their first experience as founders and executives—and then there's a different price, a different market, for repeat entrepreneurs.
What are those prices, roughly?
For first-time entrepreneurs, we've seen C deals anywhere between $15 million and $20 million post-money. For repeat entrepreneurs, we see a broader range, starting from the $40 million to $50 million range, and sometimes going up quite crazily.
You don't mind paying it because of the extra information you have about the founder on a repeat basis?
I do mind paying it. I've passed on deals where the price went crazy enough, and that's what I tell entrepreneurs: Their job is to make sure that they are the most important company in each of their investors' portfolios.
At the end of the day, they fight for attention, bandwidth, and access. When the investor's ownership goes down significantly, it's hard to become the most important company in the portfolio when an investor owns 5% of the cap table. High prices, in my view, are double-edged swords for entrepreneurs at the early stage.
How many other places do you think, in addition to cyber, this method could be applied successfully? Or is there something still in 2025 that is distinctive about cyber versus other spaces, making it by far the most fertile ground for applying something like Sunrise?
I believe that in any field where there's relative uniformity among buyers, that's applicable. I would assume it's applicable for fintech, it's applicable for gaming, and maybe it's even applicable for medical devices.
But you need a fairly active ecosystem, not just from the end user's perspective, but also from an M&A perspective. That's important as well, because not all your companies would go public. In the past 12 months, we've sold 5 portfolio companies at a cumulative value of $2.5 billion. That's important as well.
How would you rate today's environment for prospective returns? Your returns have been crazy high. Do you think the next 5 years have the chance for similar returns, or have prices made earning those kinds of returns in the market itself much harder?
Achieving amazing returns has always been super hard. It will continue to be hard, but I believe that with everything said earlier about the perfect storm in cybersecurity, the introduction of AI, and the way it's going to redefine cybersecurity, the opportunity is there.
Obviously, the quality of the talent we see is always getting better, and that's what keeps me so optimistic: seeing the endless stream of smart, eager, hardworking young individuals who are determined to build the next solutions.
Speaking of those individuals, we talked a little bit earlier about how fascinated I am by the questions that you ask. As you're identifying these people, and thinking back to your time with Mike and Doug at Sequoia—again, famous for asking people about their early lives and whole life stories—are there any other favorite questions that you like to ask people to understand them as deeply as possible that we haven't talked about?
I always speak with founders about their superpowers. What do they perceive as their superpower? What makes them confident that they can win the game?
When you speak with a founder, when you speak with an individual for a good hour, you've got a fairly good perspective of what you think is their superpower, and it's fascinating to listen to the way they perceive themselves. I found out that some of the best founders are completely unaware of their superpowers.
They are so natural at them that they don't mean to use them. They are just so great at that. A superpower can be anything. A superpower can be that you're simply the type of person that people are dying to be their friend. You don't notice that. You think that that's a gift everyone has.
You don't realize that this is your gift, and that's what paved the way for you to be successful. In many cases, the superpower they claim they have is not necessarily the real superpower they have, but it shows you the way they view their weaknesses.
The superpower they are aware of is something they pay attention to. They had to develop it, and they had to develop it in compensation for something else. So that tells you a lot about the person ahead of you.
What if you had to answer that question for yourself?
First of all, congratulations. You're a fast learner. That's great.
A few things, but I would say let's take self-confidence. That's 1 answer I would give. I'm sure this is something I've developed over time. I wasn't natural at that. It took time, and it was in compensation for a very insecure child who grew up in a small town in Israel, didn't feel really appreciated for his talents, and didn't feel that he was part of something bigger.
I think it was only when I was 13, for my bar mitzvah, that I got a Commodore 64 computer. That opened up a whole new world for me. I started to get to know people with the same mindset.
Speaking about the 1980s, I hopped on a bus and went to computer-geek gatherings in Tel Aviv when I was 14 or 15. I think it was only when I joined Unit 8200 when I was 18 that I really found out that I was part of something bigger.
I felt that I belonged to that group of people. So it took time to develop that self-confidence. Beforehand, there was always a gap between the way I felt about myself and the type of feedback I got from the people around me.
What do you think the hidden superpower is? That's your true number 1, but you're not as consciously aware of it.
My endless hunger. I'm never happy. I'm never satisfied with whatever I achieve. I always look at the next step.
I finish climbing 1 peak of the mountain, and I immediately look beyond that mountain and look for the next peak to climb. It's very daunting, because I tell myself it would be nicer if I could just take a rest and enjoy the view from the peak of the mountain I just climbed, and I find very little satisfaction in that.
Where do you find satisfaction?
Making an impact on people that I really care about. The founders I partner with are people that I really care about. My partners at Cyberstarts—Leo, Emily, Ila, and Adam—are people that I care about.
Trying to leverage the past 35 years of being on the different sides of cybersecurity, going through so many different experiences, to really make an impact on their lives.
We have the opportunity, given the timing here, to talk about an incredible investment, Wiz, which, of course, has been in the news for the last, I don't know, year in the venture world—an incredible outcome in the acquisition from Google.
We won’t talk so much about the outcome as the process and your experience and story of working with the company. We’ve talked a lot in our interview about why you do what you do, the process by which you found founders, what you look for in them, the process to find product-market fit, the Sunrise methodology, et cetera. Here we have the ultimate case study in why these ideas are powerful in combination. I would love to just hear the story from your perspective.
6. Wiz Finds Urgent Pain
You’re right. Wiz, in many ways, is the front-window use case for the Cyberstarts recipe for building an important company. For me, the Wiz story really holds many of the key ingredients for building an important cybersecurity company. I’ll talk about a few elements, and I hope that I’ll do that in the right order.
Most importantly, I think it’s picking a really important pain point and getting to perfect product-market fit. If you look at Wiz, the 4 founders—Assaf, Ami, Roi, Yaron—I think that the Wiz journey started 8 years before founding Wiz, in 2012. There was just a bunch of young guys, 27 or 28 years old, straight out of the army. Assaf had spent maybe a year with McKinsey, but they were really an inexperienced team. They started Adallom, a cloud security company, and that journey was quite short.
In 3 years, they sold the business to Microsoft, joined Microsoft in 2015, and spent 5 years at Microsoft building the Microsoft cloud security business. They brought it to a decent size of $1 billion in revenue, and then they left Microsoft in 2020. At that point in time, they were the most experienced team, in my view, worldwide in running a cloud security business.
They started a company that wasn’t called Wiz; it was called Beyond Networks, and they had a very, very different idea. They thought they would secure satellite offices with secure one access, et cetera. It was a business that never took off. At Beyond Networks, we looked at the customer feedback, and it was an important problem for customers, but it didn’t have a very important ingredient: It was important, but it wasn’t urgent.
At the early stage, as much as you like to go after large market size and an important pain point, the most important thing in my mind is to go after an urgent pain point that generates a sense of urgency. The sense of urgency is almost everything you need as a small venture, because that means that things will happen fast for you. You get more customer engagement, you learn faster, you improve faster, and you’ll be able to build your revenue faster.
We didn’t have that with the secure WAN access idea. The Wiz team was smart enough to really pivot into a space they knew very well, which is cloud security, and renamed the company Wiz. We ran a Sunrise program, which is all focused on getting feedback, making sure that we understand the pain point, and building the right solution that mere mortals can use.
3 months later, they had a product that would generate a sense of urgency. They spoke with customers, and those potential customers, those prospects, wanted to bring them in. Then I learned a very important lesson about the 4 customer profiles.
When you sell a product, you’re going to face 4 personas: the person who has the pain point, who has the problem; the person who has the budget to pay for the solution to solve that; the person who has the authority to decide on the product or solution; and the fourth person, the person who would actually use the product.
Now, as a startup, if those 4 personas map into a single person in real life, that’s a megahit, and that was the case with Wiz. If those 4 personas are mapped into 4 real people—there’s 1 real person who has the problem, 1 real person who has the budget, 1 real person who has the authority, and a fourth person who actually uses the product—don’t do that. Go and pivot.
If you map it to 2 people, that would be a very nice company. If you map it to 3 people, that’s borderline. You may or may not like to pursue that. For Wiz, it was a single person: the CISO.
The CISO has the problem. The CISO, the chief information security officer, had the authority to decide on a cloud security solution. They obviously had the budget, and most importantly, they had the AWS credentials that enabled them to really deploy the product.
Wiz was able to do something very unique just because all those 4 personas mapped into 1 real-life person. Wiz built a really cool technology. They managed to build a product that, during the first call with a prospect, they could ask for the AWS credentials and, within the call, show them real value for their own organization—not in a demo environment.
That really accelerated things for Wiz. In 3 months, we faced 1 major dilemma. We could go for a low-entry-point price product to get a lot of logos and build Wiz from the ground up, bottom up, or what people in Silicon Valley call PLG, product-led growth. Or we could go after very large deals, enterprise deals, to begin with and grow the ARR top line.
Unlike the common wisdom within Silicon Valley, we decided to go for the large deals, scrap PLG, and go for real enterprise deals to begin with. We thought that by growing our top-line ARR, we would be better off. We would have real commitment from highly sophisticated customers, attract attention from outside investors, attract attention from top go-to-market talent, and that would enable us to build a significant business.
While we spent the first 12 months building a product, the next 4 quarters were quite unusual. The company closed $1 million in ARR in the first quarter of selling the software, $2 million, I think $8 million, and then $25 million in the fourth quarter.
Wow.
It was an incredible company from the moment we actually launched our go-to-market for those 3 reasons: Focus on the urgent, not the important; build a product that has terrific product-market fit for 1 real person who owns the budget, the authority, and the ability to use the product; and sell that to large organizations at a high price point.
Can you say a little bit about how you won such early involvement with a team that was obviously so strong? The ongoing lesson from the stories that have come out since the acquisition news is that some of the very high multiples—nominal revenue multiples—were paid by subsequent-round investors who nonetheless earned an incredible return, even though they paid high multiples. I’m curious what you learned from watching that dynamic unfold, having been the earliest investor in the business.
That actually was an old lesson I learned at Sequoia many years ago: The expensive deals, the pricey companies, are pricier from day 1. They are always expensive. They’re expensive at the seed round, they’re expensive at the A round, and they’re expensive at a B round.
The worst reason for a venture capitalist to pass on an opportunity is price, because it’s part of those companies’ DNA. Pick a company. All of those companies were expensive. Airbnb was expensive. Instagram was expensive. If you’re going to pass on an opportunity just because of price, you’re going to pass on all the good companies.
Yes, Wiz was super expensive to begin with and attracted a lot of attention. It became the fastest unicorn, the fastest company to go to $100 million, and the fastest company to get to $500 million. This year, when we get to $1 billion in ARR, it’s probably going to be the fastest SaaS company to get to $1 billion in ARR.
But that’s part of the DNA. It’s a fast company. Watching that just convinced me that, as an investor, a high-priced company is actually a good thing, not a bad thing, if justified.
Is there any other novel lesson? I love the 3 points that drove the success that you outlined, and I love the idea that the high-price thing is an old lesson. Are there any other new lessons that Wiz taught you that are unique to your experience with that specific company?
The productivity at Wiz, if you look at it, was second to none. When I looked at the number of engineers relative to the number of products and the number of capabilities we delivered annually, it was amazing.
When I look at the way Wiz sourced engineers, there’s always a debate: How do you pick the best engineers, and who are the best engineers for your business? I discussed that with Roi Reznik, the VP of R&D at Wiz, one of the 4 co-founders, and he had a super-special way to source engineers.
He would not just source smart engineers who had been at good companies beforehand, had terrific educations, et cetera. He would source people whose hobby was writing code. He would source people who, on a weekend, assuming they were married and had kids, if they had a couple of hours of quiet time, would not go reading or watch a Netflix series or listen to music. They would go and write code.
Those are the people you like to hire. When you have 100 of these guys, it’s like having 300 or 400 terrific engineers, because you know the rule that a great software developer is probably 10 times better than a good software developer. Having great software developers whose hobby, whose sole hobby, is writing code—that’s a force multiplier. I think Wiz realized that and capitalized on it.
Is the outcome satisfying?
I think I told you as part of the interview that I’m never satisfied, so—
Just testing it.
The answer is no. I know that you’re going to laugh and say, “Okay, I really feel that.” But again, it’s hard to live life twice. I wish I could. I would A/B-test that decision again.
But I think it’s setting the bar super high to get from $0 to a $32 billion valuation within 5 years.
I didn't check the history books, but I guess that's pretty good. But I can think about a few other companies that have the potential, at least, to break that record. I dare to predict, again, assuming this transaction goes through and gets approved, et cetera, and that's the real final outcome, my guess is that within 10 years, somebody will break that record.
Do you think it can be broken in cybersecurity specifically?
Yes.
Why? Why do you think that's possible? Just because it's changing and so big?
Because you have all the ingredients. You've got the market size, you've got the evolving pain point, a fast-moving threat landscape, and a lot of talent. A lot of experienced talent, not just on the engineering side, but also on the business side. And I think that you have some experienced investors as well.
So I think that you've got the ingredients. Now, luck should be in the mix as well, and therefore I think that within the next decade, we would see that record getting achieved and broken by a new player. I think it's very, very feasible.
If it happens, I wouldn't be surprised if you're involved from the very earliest stages, and if the Sunrise methodology and your approach works again.
I appreciate that.
If you think about the stories of resilience that you look for in your founders, it's a nice thing to say. Can you tell me the story of the hardest episode of resilience that you've had to personally go through?
7. Living With Terrible Pain
Before starting Cyberstarts, I lost my daughter, my 19-year-old daughter, in a terrible tragedy. The world just paused for me, and it was very easy to stop everything and focus on the endless pain I felt. I managed to find the power and the strength to keep on going, build Cyberstarts, and focus on building that organization and legacy. That really helped me to continue to live with the pain, but continue to live.
How is that possible? Everyone listening, myself included, with children, knows that's the single worst thing one could imagine. How is it possible to get beyond something like that?
I think it's very, very difficult to give advice. Hopefully nobody has to deal with that tragedy. It's really the most painful thing that you can go through.
For myself, I did that instinctively. I didn't spend time thinking about it. I didn't make a decision. I just did it. In a way, I managed to live with terrible emotions that previously I wouldn't have imagined I could contain and live with. Over time, I taught myself to live with the pain, not fight the pain. Just wait for the pain to ease.
And I think that working with younger people on innovation, on solving real-world problems, and on building solutions, that is what kept me younger and healthier.
I love the message of focusing on young people and building things for others. It seems like your orientation, your satisfaction, your strategy, your search, and your work are very other-oriented. Anything you would say to other investors out there who hear that part of your story, and that's the piece that appeals to them most—helping other people in what they build and how they do their work?
I really think that there are many ways to become a terrific investor. I don't think there's one canonical way to get there. By the way, it's not enough just to be first. You also need to be right. That's the difference between an investor and a terrific investor: being right.
But again, there are many ways to hell, but there's also more than one way to heaven. My recommendation is to really find your passion and do something that's not just profit generation or work. Do something that's a life project for you.
When I look at cybersecurity, cybersecurity is not an investment area. It's not an area of interest for me. It's a life project. It's really important for me, and I think that's the best thing you can feel about anything you do: that it's super, super important to you. You really care about it.
If you think about the future of cyber, what challenges, evolutions, or things that might happen excite you most? Or worry you most? I guess both.
It's not the way I think about the future of cybersecurity. I don't keep a category of domains, et cetera. It's a common misconception to think about cybersecurity as a market. Standalone, there's no cybersecurity market. Cybersecurity is always a derivative of something else, of a new technology or a new business.
So if cloud is new, you need cloud security, and if autonomous vehicles are new, you need autonomous vehicle security. Take, for instance, our conversation about AI. AI will for sure redefine cybersecurity. It already does, but you couldn't predict it.
So, as an investor that focuses on early-stage cybersecurity investment, I'm not concerned about figuring out the best, the most important things or opportunities or domain in cybersecurity. I'm confident they will introduce themselves, the same as cloud introduced itself, IoT security introduced itself, mobile security introduced itself, and AI security introduced itself.
I'm focused on picking the right talent, picking the right athletes, partnering with them, and making sure that you use the right system. See our conversation around Sunrise to really build solutions that real customers and real users would love. If we do that, everything else will fix itself.
It's totally remarkable what you built in a short period of time. I'm sure the Cyberstarts story is in its infancy, and that we'll be able to do this in 5 years, and a whole new set of challenges will have arisen, like you said, probably unpredictable.
Thank you for doing this with me. When I do these, I always ask the same traditional closing question. What is the kindest thing that anyone's ever done for you?
The kindest thing that someone has done for me is that, a couple of years ago, my son told me that he spent a lot of time thinking about it, and he realized that I'm his best friend. For me, that was probably the best thing anyone could tell you.
It's not just about being a dad. It's the ability to create this level of trust and emotional connection that makes someone feel that you are his best friend. And when it comes from your son, that's the kindest thing you can hear from anyone.
Close to 500 times, I've never heard that answer. These answers tend to cluster in a couple of key themes, variants of key themes, three or four. I've never heard that one. With a son of my own, it hits you right in the face. All that must have gone into that thing he told you. Really a beautiful, amazing place to close.
Gili, thanks so much for your time.
Thank you, Patrick. I really enjoyed it.