Data Breaches Boost Funding for Cybersecurity Startups

BT-AD101_CYBERV_16U_20150715182705.jpg

In the 2015 first half, venture firms invested $1.2 billion in cybersecurity startups
 
Before Max Krohn, the OkCupid co-founder, played online matchmaker, he had a far-less-romantic interest in cryptography. But he couldn’t see a way to make a living at it.
“Security startups never really did so well,” says Mr. Krohn, who studied computer science at Harvard University and the Massachusetts Institute of Technology. “There was not an example of a runaway success.”
That is changing, following major data breaches, as corporate customers and venture capitalists show increased interest in cybersecurity. Mr. Krohn and another OkCupid co-founder have a new startup, Keybase, which aims to make encryption easier to use. Wednesday drew its first outside investment, a $10.8 million round led by venture-capital firm Andreessen Horowitz.
On Monday, Google Capital, the search giant’s growth-equity fund, made its first cybersecurity investment, leading a $100 million round in Crowdstrike, known for outing Chinese and Russian hackers. Allegis Capital this month said it closed on $100 million toward a fund focused on cybersecurity. Three years ago, private-equity fund Blackstone Group had no cybersecurity investments; now it has seven.
“It’s almost like, ‘Who hasn’t been hacked?’ ” said Venky Ganesan, a managing director at Menlo Ventures who led the firm’s investment in BitSight Technologies, which gives companies a credit-score-like rating for computer defenses. In 2011, Menlo directed about 5% of a $400 million fund toward security startups, Mr. Ganesan said, and its current fund has dedicated about 20% to the field.

In the 2015 first half, venture firms invested $1.2 billion in cybersecurity startups, according to researcher CB Insights. That is down slightly from $1.4 billion a year earlier but up sharply from $771 million in 2013’s first half.
The shift is particularly notable at Andreessen Horowitz, which used to view security companies as necessary for Internet safety but less lucrative than other technology niches.
One reason is that cybersecurity startups were often acquired prior to an initial public offering, says Scott Weiss, an Andreessen Horowitz partner. Mr. Weiss sold his own security startup, IronPort Systems Inc., to Cisco Systems Inc. for $830 million in 2007.
Well-received offerings from companies including Palo Alto Networks Inc. in 2012 and FireEye Inc. in 2013 have altered that view. Partners at Andreessen Horowitz say they likely wouldn't have invested in a company like Keybase even two years ago. Over the past 13 months, the firm also made an unusually large $142 million bet on Tanium Inc., which tries to make it easier for companies to find vulnerable and infected machines on their networks.
Ted Schlein, a partner at Kleiner Perkins Caufield & Byers who has invested in security startups for two decades, says he has noticed more investors jumping into cybersecurity.
That is a risk for investors in cybersecurity companies, as is the rush of entrepreneurs suddenly flooding the space. Bob Ackerman, a managing director of Allegis Capital and another longtime investor in cybersecurity, says he sees a lot of me-too companies led by founders without experience in the field.
“This isn’t sharing-economy stuff,” says Mr. Ackerman, referring to companies like Uber Technologies Inc. and Airbnb Inc. that connect individuals looking for rides or rooms. “This is nerdy stuff.”
Another risk, Mr. Ackerman notes, is that every new piece of security technology is one data breach away from being obsolete.
Core to Keybase’s pitch is making it easier for users to trade public encryption keys, a crucial step in using PGP, the encryption protocol formally called Pretty Good Privacy. PGP is considered secure, but it’s clunky and nowhere near as simple as Facebook or Google.
Chris Dixon, the Andreessen Horowitz partner who led the investment, said he expects Keybase to let individuals use the service for free but charge enterprises for extra features. Krohn, the cofounder, said he wants to offer users an encrypted file-sharing tool and encrypted chat applications.
As a Harvard student in the late 1990s, Mr. Krohn worked on websites during the first tech boom alongside programmers with a hacking background. The interest rubbed off, he said.
After graduating in 1999, however, he and his friends were more interested solving more immediate problems, like dating. Hence OkCupid.
Mr. Krohn left the dating site in 2012 and pondered his next move with cofounder Chris Coyne. They became intrigued with simplifying encryption, and launched Keybase last year.
They initially didn’t see much commercial future in the startup, and spurned investment offers from venture capitalists, Messrs. Krohn and Dixon said.
A few breaches later, they too began to see it as a business.
“Five years ago, it would have been a very hard sell,” Mr. Krohn said. “Probably, it would have been, ’Sorry, no one cares about security, therefore this product doesn’t have much of a hope.’ ”
WSJ: http://on.wsj.com/1HweA7Z

« SurfWatch Labs Rolls Out Dark Web Intelligence Service
How Analytics Will Influence Connected Cars »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Zurich

Zurich

Zurich is a leading multi-line insurer providing a wide range of property and casualty, and life insurance products and services in more than 210 countries and territories.

Prim'X Technologies

Prim'X Technologies

Prim'X Technologies provides information protection solutions to prevent unauthorised access to sensitive data.

Cyber8Lab

Cyber8Lab

Cyber8Lab provides cybersecurity training programmes simulating real world cybersecurity incidents such as web defacement, malware, phishing, digital forensics analysis and wireless intrusion.

Infodas

Infodas

Infodas provides Cybersecurity and IT consulting / system integration services as well as a range of innovative Cybersecurity products to public sector and commercial clients.

Swascan

Swascan

Swascan is the first all-in-one, GDPR Compliant, Cloud Security Suite Platform. GDPR Assessment, Web Application Scan, Network Scan, Code Review.

Evanston Technology Partners (ETP)

Evanston Technology Partners (ETP)

ETP provides services and solutions to enable and transform businesses in the areas of cybersecurity, data protection, and efficient operations practices.

ThreatSwitch

ThreatSwitch

ThreatSwitch a software platform for cleared federal contractors to get and stay compliant with NISPOM and Conforming Change 2.

Beauceron Security

Beauceron Security

Beauceron's cloud-based platform gives employees a powerful personal cyber-risk coach empowering them to improve their cybersecurity practices and behaviours.

Eastern Cyber Resilience Centre (ECRC)

Eastern Cyber Resilience Centre (ECRC)

The Eastern Cyber Resilience Centre is part of the national roll out of Cyber Resilience Centres in the UK which began in 2019.

Outsource Group

Outsource Group

Outsource Group is an award winning Cyber Security and IT Managed Services group working with a range of SME/Enterprise customers across the UK, Ireland and internationally.

National Coordinator for Security and Counterterrorism (NCTV) - Netherlands

National Coordinator for Security and Counterterrorism (NCTV) - Netherlands

The NCTV serves the Netherlands’ national security. We protect national interests, identify threats and strengthen resilience.

ExactTrak

ExactTrak

ExactTrak provide embedded cyber security solutions for your digital devices – whenever and wherever you need them.

BBS Technology

BBS Technology

BBS Technology is a company that develops and delivers next-generation cyber security technologies worldwide.

Razilio

Razilio

Razilio is a boutique cybersecurity consultancy located in Sydney, Australia and serving the world.

Boldend

Boldend

Boldend offers leading-edge offensive and defensive cybersecurity solutions that empower government and commercial organizations to stay resilient in an evolving threat landscape.

GetReal Security

GetReal Security

GetReal Security is the world’s leading authority on malicious digital content and deepfake protection.