{"id":5290,"date":"2024-09-12T14:18:11","date_gmt":"2024-09-12T19:18:11","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/cybersecurity-influence-startup-investment"},"modified":"2024-09-12T14:18:11","modified_gmt":"2024-09-12T19:18:11","slug":"when-startup-founders-should-start-thinking-about-cybersecurity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/12\/when-startup-founders-should-start-thinking-about-cybersecurity\/","title":{"rendered":"When Startup Founders Should Start Thinking About Cybersecurity"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta989e771a2914afa\/66df4b0d00614b17695cb394\/Startups-Illia_Uriadnikov-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It was a tale of two startups.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A company that I invested in \u2014 about, oh, five years ago \u2014 happened to be in the proptech [property technology] space,&#8221; David Rose, managing partner at Rose Tech Ventures, said during a panel at Cybertech NYC last week. The property tech startup he was referring to helped people build their credit by paying their rent with credit cards. &#8220;So it was a really cool company [and] it was going great. And then it turned out they had been hit by scammers, who were setting up fake buildings and fake credit cards, using them [for fraud]. And the entire company blew up because of that.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another company from one of Rose&#8217;s prot\u00e9g\u00e9s had a similar idea and business model, but because the company had better security, they were able to grow. &#8220;So you see a company that had really interesting ideas, demonstrated a great potential, smart guys, but the company got killed because of cyber,&#8221; Rose noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Startups are valued for their forward thinking, their financials, their talent. No investment negotiation has ever broken down over the issue of cyber preparedness. Yet, clearly, an incident can be catastrophic to a promising but volatile new business, and anecdotal evidence suggests investors and founders alike are starting to take that risk seriously.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Threat to Startups\">The Threat to Startups<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Volt Typhoon, the Chinese advanced persistent threat (APT) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">du jour<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, has compromised critical infrastructure providers of every kind \u2014 internet service providers, electric utilities, wastewater treatment, energy, and more \u2014 on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/voltzite-zaps-african-utilities-volt-typhoon-onslaught\" rel=\"noopener\">multiple continents<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and targeted <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/china-s-volt-typhoon-apt-burrows-us-critical-infrastructure\" rel=\"noopener\">military organizations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> along the way. Its attacks are of the highest caliber among known APTs. But a few weeks ago, it went after a different type of prey: a startup.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Versa Networks <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/versa-networks.com\/news\/2021\/versa-networks-named-hot-startup-to-watch-in-2021-big50-startup-report\/\" rel=\"noopener\">attracted a lot of attention<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with its secure access service edge (SASE) software-as-a-service offering and earned $120M in pre-IPO funding in October 2022. Less headline-grabbing was a bug in its software-defined wide area networking (SD-WAN) technology (CVE-2024-39717). The vulnerability \u2014 rated as &#8220;high&#8221; severity with a CVSS score of 7.2 \u2014 allowed Volt Typhoon to push a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-s-volt-typhoon-actively-exploiting-now-patched-0-day-in-versa-director-servers\" rel=\"noopener\">custom, credential-grabbing web shell<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> through the Versa Director platform, allowing the attackers to breach four Versa customers in the United States and one in India.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though attacks and breaches can happen to any company, startups like Versa Networks, security camera firm Verkada \u2014 which was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/08\/ftc-takes-action-against-security-camera-firm-verkada-over-charges-it-failed-secure-videos-other\" rel=\"noopener\">fined $3 million by the FTC last month<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> following its breach where attackers took over customer cameras \u2014 and Rose&#8217;s proptech failure are particularly vulnerable. Like any small or medium-sized businesses, they might struggle with budgets and resource allocation. More so than other businesses, though, startups sell excitement and promise. Where a typical business might aim to be secure, but simply lack the money and manpower to do it right, startups that aim to move fast and break things might simply deprioritize a cost that does not incur growth.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Rose told Dark Reading at Cybertech, &#8220;In the case of the company that I mentioned, it [cybersecurity] hadn&#8217;t even occurred to them. They were thinking about the upside [of the business], not the downside.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unfortunately, the answer to securing startups isn&#8217;t straightforward.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"When Startups Need to Think About Security\">When Startups Need to Think About Security<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When established companies shift their attention to beefing up their cybersecurity, they typically invest in personnel, training, and layered security software (among other things). But as Rose points out, &#8220;Virtually no founders we are speaking with are facing cyber security challenges because they don&#8217;t have any product!&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Startup security is a more nuanced matter which largely rests on timing, explains Bob Ackerman, founder and managing director of the early-stage VC company AllegisCyber. &#8220;When you&#8217;re looking at a stage zero startup, security probably is not the number one consideration. It&#8217;s, &#8216;Is this a good idea?&#8217;, &#8216;Can this team perform?&#8217;, &#8216;Is there actually a business here?&#8217; But as companies gather steam, establish critical mass, the consequences of getting cybersecurity wrong increase,&#8221; Ackerman says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Usually a mid-stage or later-stage company has enough cybersecurity questions for it to be obvious that we need a security team, a security program, [and] a security budget as well,&#8221; says Will Lin, author of The VC Field Guide. &#8220;If I were to force a number, I would say that for companies over, say, 3,000 employees, it starts becoming more of a key topic for investors.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lin cautions, though, that needs vary widely across companies of different kinds. &#8220;You might find very, very large organizations \u2014 even above 3,000 people, for example \u2014 that have a tiny, three-person-or-less security team, and then you might find a small organization of 200 people spending quite a lot per year on security. Security budgets and programs and everything tends to be more reactive than [saying] &#8216;Obviously, the next step of the company is we need to do X, Y, Z,&#8221; Lin explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The variation occurs not just due to size and maturity, Ackerman adds, but also industry. &#8220;Maybe a financial services company is going to have cyber risk exposure, and so [be] aware of it from a very early stage, particularly in sectors like financial services, where there is a lot of personally identifiable information, or anything in supply chain, where a compromise could be disruptive and have an adverse consequence,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Nudging Security to a Higher Priority\">Nudging Security to a Higher Priority<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.embroker.com\/blog\/cyber-risk-report-founders-cyber-security\/\" rel=\"noopener\">February survey<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from business insurance company Embroker, more than two thirds of founders have experienced a cyberattack against one of their businesses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Founders seem to be extra cautious about security. In the survey, 86% reported owning some kind of cyber insurance, and 71% were considering additional security protections in addition to having insurance. About a third (31%) of the respondents reported being more concerned with security than they were the year prior.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Those who aren&#8217;t thinking about cybersecurity may be nudged into doing something by the investors themselves. As Rose points out, &#8220;One of the things that we have on our standard investor checklist when we do full-on due diligence is: What is your cybersecurity plan? How is it going to work? Actually, in many cases, it&#8217;s the first time anybody ever asked the startup founder about security.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He continues, &#8220;I would be very happy if they have something in their deck \u2014 at least in their appendix to their deck \u2014 which would say: &#8216;Here&#8217;s our thoughts, here&#8217;s our plan, here&#8217;s our vulnerability.&#8217; Just tell me that you&#8217;ve actually given more than two-and-a-half minutes worth of thought to the subject, and you will be ahead of 95% of other companies.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More mature, later-stage startups need to start making material investments, and hiring for executive positions, he explains, &#8220;And if you&#8217;re a platform business that is open to the public, and you&#8217;ve got any kind of money going anywhere, then you damn well better have a really serious plan.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If the world was under my control, I would say: Yes, as a startup founder with no paying clients until next year, I want you thinking about building in security from day one. But because that doesn&#8217;t tie out to dollars day one \u2014 and startups are always pressed for dollars, always trying to move fast and break things \u2014 that&#8217;s a very hard sell,&#8221; he admits.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cybersecurity-influence-startup-investment\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It was a tale of two startups. &#8220;A company that<\/p>\n","protected":false},"author":12,"featured_media":5291,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5290","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=2560%2C1438&ssl=1",2560,1438,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=300%2C168&ssl=1",300,168,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=640%2C359&ssl=1",640,359,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=640%2C359&ssl=1",640,359,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=1536%2C863&ssl=1",1536,863,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=2048%2C1150&ssl=1",2048,1150,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=1024%2C575&ssl=1",1024,575,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/when-startup-founders-should-start-thinking-about-cybersecurity-scaled.jpg?fit=2560%2C1438&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5290","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5290"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5290\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5291"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}