Listen Here

| |

Conversation
Highlights

Building a Category in Cybersecurity: When Excel Sheets Run Fortune 500 Security Programs

Excel sheets running billion-dollar company security programs – this was the reality that drove Sivan Tehila to build Onyxia. In a recent episode of Category Visionaries, the former IDF cybersecurity officer shared a startling discovery that shaped her company’s trajectory: “Almost any Fortune 500 CISO I spoke with showed me an Excel sheet that they’re managing since they started their position as a CISO in any company.”

This revelation exemplifies a broader challenge in enterprise cybersecurity: while companies invest heavily in security solutions, the management of these programs remains surprisingly manual. “It’s just unbelievable that in 2023, Fortune 500 companies, sea level people, still need to manage all their efforts in an Excel sheet,” Sivan notes.

The journey to address this problem wasn’t straightforward. When Sivan first approached investors with the concept of cybersecurity performance management, she encountered significant resistance. “When I started, no one was talking about security performance at all,” she explains. “Most of the products in this space were related to GRC governance, risk and compliance, and those more of a traditional risk quantification products.”

Rather than conforming to existing categories, Sivan chose to focus on solving the core problem. This decision would prove crucial in navigating the complex dynamics of category creation. “We don’t want to build a product that is aligned necessarily with what Gartner’s defined category. We want to solve a problem,” she emphasizes, highlighting a key lesson for founders creating new market categories.

The emergence of new SEC regulations has created additional momentum for innovative approaches to security management. As Sivan explains, “Companies need to disclose their security programs and strategies, and to have at least one board member with cybersecurity expertise.” This regulatory shift has prompted companies to reassess their security management approach: “Many companies I spoke with a while ago got back to me recently and they told me, ‘hey, Sivan, we’re thinking about your product with their relation to the SEC regulation.'”

For founders entering the cybersecurity space, Sivan emphasizes the importance of precise problem definition. “Because cybersecurity is a very overwhelming space… really doing your research around the problem and define the solution in a very clear way could be very helpful,” she advises. The alternative? “Often when investors hear your pitch, they really feel like they heard that 100 times before you showed up.”

Looking ahead, Sivan envisions transforming how security leaders start their day. “My dream was to be able to wake up in the morning, like I’m asking Alexa ‘how’s the weather today?’ To be able to go to one place and ask ‘what are the top three things I should be afraid of today?'” This vision of seamless security management extends beyond traditional web interfaces – Onyxia has built both web and mobile applications, recognizing that modern security leaders need flexibility in how they access and manage their programs.

The company’s approach to fundraising offers another valuable lesson for founders. Rather than rushing to secure capital, Sivan focused on building meaningful relationships with potential investors. “I really felt that I need to build a relationship with my investors,” she shares. “Now any investor in my cap table brings value to the company that is not just the money they were putting in.”

As cybersecurity continues to evolate, the need for better program management becomes increasingly critical. By focusing on solving a specific, widespread problem rather than fitting into established categories, Sivan demonstrates how founders can successfully navigate category creation while building solutions that address real customer needs.

For B2B founders, the key takeaway isn’t just about identifying a problem – it’s about having the conviction to solve it in a way that might not fit neatly into existing market categories. As Sivan’s experience shows, sometimes the best opportunity lies in challenging the status quo, even if that means taking on the additional challenge of category creation.

Actionable
Takeaways

Leverage Regulatory Tailwinds to Drive Adoption:

Sivan highlights how recent SEC regulations requiring companies to disclose security incidents, programs, and strategies have increased demand for Onyxia's solution. By staying attuned to the regulatory landscape and proactively positioning your product as a compliance enabler, you can ride the wave of urgency and budget allocation that often follows new mandates. Founders should monitor relevant regulations and adapt their messaging accordingly.

Prioritize Investor Fit Over Brand Name in Fundraising:

In her first fundraising experience, Sivan learned the value of building genuine relationships with investors who bring more than just capital to the table. Rather than chasing big-name firms, she focused on finding investors who believed in her vision, provided valuable expertise, and made meaningful introductions. Founders should prioritize investor fit and long-term value alignment over short-term signaling.

Differentiate Through Crisp Problem Definition in Crowded Markets:

To stand out in the noisy cybersecurity market, Sivan emphasizes the importance of crisply defining the specific problem you're solving and articulating why your approach is unique. By avoiding generic buzzwords and focusing on tangible customer pain points, you can cut through the clutter and capture investor attention. Founders should strive for clarity and precision in their problem statements.

Design for Executive Ease of Use with Mobile-First Experiences:

Onyxia differentiates itself by offering a mobile app that enables CISOs to quickly access key insights and manage their security efforts on the go. By designing for the unique needs and workflows of executive users, the company creates a stickier and more valuable experience. Founders should consider how mobile-first design can empower their target personas and drive adoption.

Focus on Solving Customer Problems, Not Conforming to Analyst Frameworks:

While acknowledging the influence of analyst firms like Gartner in shaping market categories, Sivan cautions against building products solely to align with their frameworks. Instead, she advises founders to stay laser-focused on solving real customer problems and trust that the category definitions will evolve to reflect the value they deliver. Don't let analyst taxonomies dictate your roadmap at the expense of customer needs.

Recommended Founder
Interviews

Pukar Hamal

CEO and Founder of SecurityPal

Pukar Hamal, CEO and Founder of SecurityPal: $21 Million Raised to Power the Future of Customer Assurance

Michael Assraf

CEO & Co-Founder of Vicarius

Michael Assraf, CEO of Vicarius: $29 Million Raised to Build the Future of Vulnerability Prioritization

Ori Eisen

CEO & Founder of Trusona

Ori Eisen, CEO & Founder of Trusona: $38 Million Raised to Power the Future of Account Takeover Prevention

Tiffany Ricks

CEO and Founder of HacWare

Tiffany Ricks, CEO and Founder of HacWare: $2.6 Million Raised to Build the Future of Security Awareness

Robert Cowart

CEO & Co-Founder of ElastiFlow

Robert Cowart, CEO & Co-Founder of ElastiFlow: $8 Million Raised to Power the Future of Network Performance and Security Analytics

Colby Proffitt

VP of Marketing of Shift5

From the Pentagon to B2B: Colby Proffitt’s Journey and ABM Insights

Mollie Breen

CEO and Co-Founder of Perygee

Mollie Breen, CEO and Co-Founder of Perygee: $6.4 Million Raised to Build the Future of IT/OT Security

David Etue

CEO of Nisos

David Etue, CEO of Nisos: $33 Million Raised to Build the Future of Managed Intelligence

Dave Mor

CEO and Co-Founder of OneLayer

Dave Mor, CEO and Co-Founder of OneLayer: $15 Million Raised to Protect Private Cellular Networks

Matteo Bogana

CEO and Co-Founder of Cleafy

Matteo Bogana, CEO & Co-Founder of Cleafy: $12 Million Raised to Build the Future of Online Fraud Prevention

Josh Shaul

CEO of Allure Security

Josh Shaul, CEO of Allure Security: $6 Million Raised to Help Businesses Win the Battle Against Online Scammers

John Milburn

CEO of Clear Skye

John Milburn, CEO of Clear Skye: More Than $20 Million Raised to Build the Future of Identity and Access Governance

Scott McCrady

CEO of SolCyber

Scott McCrady, CEO of SolCyber: $20 Million Raised to Build the Future of Managed Security

Justin Beals

CEO, Co-Founder of Strike Graph

Justin Beals, CEO of Strike Graph: $12 Million Raised to Build the Future of Automated Security and Compliance

Ken Bagnall

CEO & Founder of Silent Push

Ken Bagnall, CEO & Founder of Silent Push: $22 Million Raised to Transform Threat Intelligence Through Adversary Infrastructure Monitoring

Jason Martin

Co-Founder and Co-CEO of Permiso Security

Jason Martin, Co-Founder and Co-CEO of Permiso Security: $10 Million Raised to Build the Future of Cloud Security

Neil Serebryany

CEO and Co-Founder of CalypsoAI

Neil Serebryany, CEO & Co-Founder of CalypsoAI: $38 Million Raised to Power the Future of AI Security

Stephen de Vries

CEO and Co-Founder of IriusRisk

Stephen de Vries, CEO and Co-Founder of IriusRisk: $40 Million Raised to Build the Future of Threat Modeling

Jean Le Bouthillier

CEO of Qohash

Jean Le Bouthillier, CEO of Qohash: $20 Million Raised to Build the Future of Data Security

Arjun Bhatnagar

CEO & Co-Founder of Cloaked

Arjun Bhatnagar, CEO of Cloaked: $25 Million Raised to Build the Future of Data Privacy

Peter Prizio Jr

CEO of SnapAttack

Peter Prizio Jr, CEO of SnapAttack: $8 Million Raised to Power the Future of Threat Management

Sebastian Stranieri

CEO & Founder of VU Security

Sebastian Stranieri, CEO & Founder of VU Security: $24 Million Raised to Build the Future of Digital Identity & Fraud Prevention

Danny Lopez

CEO of Glasswall

Danny Lopez CEO of Glasswall: $60+ Million Raised to Make the Content Disarm and Reconstruction (CDR) Category Mainstream

Nadav Arbel

CEO & Co-Founder of Cyrebro

Nadav Arbel, CEO & Co-Founder of Cyrebro: $51 Million Raised to Build the Future of ML-Backed MDR

Edward Wu

CEO and Founder of Dropzone AI

Edward Wu, CEO & Founder of Dropzone AI: $20 Million Raised to Build the Future of AI SOC Analysts

Eric Olden

CEO and Founder of Strata Identity

Eric Olden, CEO and Founder of Strata Identity: $42 Million Raised to Build the Identity Orchestration Category

Dan Lorenc

CEO & Founder of Chainguard

Dan Lorenc, CEO & Founder of Chainguard: $250 Million Raised to Power the Future of Software Supply Chain Security

Aurelie Guerrieri

Chief Marketing & Alliances Officer of DataDome

Aurelie Guerrieri, Chief Marketing & Alliances Officer at DataDome: 20 Years in Silicon Valley – Insights on the Evolving Tech Landscape

Ian Amit

CEO and Founder of Gomboc

Ian Amit, CEO & Founder of Gomboc: $5 Million Raised to Build the Future of Cloud Security Remediation

Ryan Lasmaili

CEO & Co-Founder of Vaultree

Ryan Lasmaili, CEO of Vaultree: $16 Million Raised to Build the World’s First Fully Functional Data-in-Use Encryption

Marina Segal

CEO and Co-Founder of Tamnoon

Marina Segal, CEO & Co-Founder of Tamnoon: Over $5 Million Raised to Build the Future of Cloud Security

Rodrigo Leme

Marketing Director of Right-Hand Cybersecurity

Rodrigo Leme, Marketing Director at Right-Hand Cybersecurity: Standing Out in a Crowded Market – Niche Targeting and Customer-Centric Approach

Stijn Vande Casteele

Founder of Sweepatic

Stijn Vande Casteele, Founder of Sweepatic: $4.4 Million Raised to Build the Future of External Attack Surface Management

David Brumley

CEO of Mayhem

David Brumley, CEO of Mayhem: $38 Million Raised to Build the Future of Security Testing

Austin Gadient

CTO & Co-Founder of Vali Cyber

Austin Gadient, CTO & Co-Founder of Vali Cyber: $15 Million Raised to Build the Future of Linux Security

Mykolas Rambus

CEO & Co-Founder of Hush

Mykolas Rambus, CEO & Co-Founder of Hush: $7.5 Million Raised to Build the Future of Data Privacy

Bill Moore

CEO and Founder of XONA

Bill Moore, CEO and Founder of XONA: $30 Million Raised to Build the Future of OT User Access

Umaimah Khan

CEO and Co-Founder of Opal Security

Umaimah Khan, CEO & Co-Founder of Opal Security: $32 Million Raised to Build the Future of Identity Security

Itzik Alvas

CEO & Co-Founder of Entro Security

Itzik Alvas, CEO & Co-Founder of Entro Security: $24 Million Raised to Build the Future of Non-Human Identity Management

Paul Valente

CEO and Co-Founder of VISO Trust

Paul Valente, CEO and Co-Founder of VISO Trust: $17 Million Raised to Build the Future of Third-Party Cyber Risk Management

Tom Jermoluk

CEO of Beyond Identity

Tom “TJ” Jermoluk, CEO of Beyond Identity: $200 Million Raised to Build the Future of Multi-Factor Authentication

Russell Spitler

CEO & Co-Founder of Nudge Security

Russell Spitler, CEO & Co-Founder of Nudge Security: $17 Million Raised to Build the Future of SaaS Security

Christian Almenar

CEO & Co-Founder of Monad

Christian Almenar, CEO of Monad: $19 Million Raised to Solve the Cybersecurity Big Data Problem

Ayal Yogev

CEO and Co-Founder of Anjuna

Ayal Yogev, CEO and Co-Founder of Anjuna: $42 Million to Build The Future of Confidential Computing

Kyle Hanslovan

CEO & Co-Founder of Huntress

Kyle Hanslovan, CEO of Huntress: $160 Million Raised to Build the Future of Managed Security

Ryan Schonfeld

Founder & CEO of Hivewatch

Ryan Schonfeld, CEO of Hivewatch: $25 Million Raised to Build the OS of Physical Security

Philippe Humeau

CEO of CrowdSec

Philippe Humeau, CEO of CrowdSec: $21 Million Raised to Build the Future of Cyber Threat Intelligence

Paul Lewis

Founder and CEO of Calamu

Paul Lewis, CEO of Calamu: $20 Million Raised to Build the Cyber Storage Category

Spencer Thompson

CEO and Co-Founder of Prelude

Spencer Thompson, CEO and Co-Founder of Prelude: Over $30 Million Raised to Build the Future of Continuous Security Testing

Ani Chaudhuri

CEO & Co-Founder of Dasera

Ani Chaudhuri, CEO & Co-Founder of Dasera: $21 Million Raised to Build the Future of Data Security

Arie Zilberstein

CEO and Co-Founder of Gem Security

Arie Zilberstein, CEO and Co-Founder of Gem Security: $34 Million Raised to Power the Future of Cloud Detection and Response