3 ms·
I spent twelve years as a "security guy" before becoming employee #1 at a now-wildly-successful security startup five years ago. I've spent a lot of time in th
by jjguy 9y ago
I spent twelve years as a "security guy" before becoming employee #1 at a now-wildly-successful security startup five years ago. I've spent a lot of time in the last year "professionalizing" our security program, now that we've grown large enough to need repeatable security procedures. I am intimately familiar with the domain.
Three things to segment the space:
- Clients are typically driven by compliance or practical security value. Understanding who you cater to and qualifying your customers will save a lot of pain.
- Many/most "pentesting" firms are focused on the corporate enterprise and IT people, not SaaS and dev people. Recognizing the difference in yourself and your customer needs will save a lot of pain.
- Many/most of the traditional IT enterprise security best practices & tools do not apply to a well-managed SaaS platform. e.g., I do not need a traditional vuln scanner to check for unnecessary and vulnerable services when I have one domain that's terminated at an AWS ELB.
Some industry color:
- The 2013 Target compromise root cause was not Target themselves, but their HVAC contractor who maintained trusted access. As a result, third party vendor risk assessment is becoming "standard practice" during the procurement process of any technology vendor, including SaaS applications.
- The vendor risk assessment teams expect all vendors to have mature security programs - SSAE-16 SOC2 audits, full Secure Development Lifecycle practices and customer-facing documentation to describe it all in detail.
- The result is a growing demand amongst smallish SaaS vendors for more professional security guidance.
With that context, some commentary on your original question:
- There are very few firms that provide good "practical security value." I cannot find enough good pen-testing firms that are a reasonable proxy for a capable attacker.
- The market for firms providing "compliance" services to "corporate enterprise IT" shops is noisy and full. The market for providing similar services to smallish SaaS vendors/developers is very sparse.
- The security tooling for dev is pretty good - static & dynamic source code analysis, tied into the build pipeline, etc. The security tooling for devops is not. There is a large gap in security tooling for devops/SaaS vendors - distinguished by automation and focus.
Finally, commentary on the question you're really asking:
- If you are world-class good, or can build a world-class team, you can build an outstanding company providing practical security value pentest services. Scale will be limited by the number of world-class staff you can hire/train.
- There is a gap in providing higher-level services to smallish startups to help them navigate third party risk assessment procedures from their customers. HN's tptacek and elptacek recently launched a new consultancy with this focus. They nailed the product/market fit. [a, b] Again, scale will be limited by the number of staff you can hire/train, but it is an easier team to grow than world-class attackers.
- There is a gap in security toolchains for devops/SaaS providers. Review the public projects from Netflix, Facebook and the other SaaS heavies for specific gaps _they_ had to fill. Every one is a product waiting to happen.
Cheers, and good luck.
a - https://latacora.com/ https://latacora.com/
b - https://news.ycombinator.com/item?id=12567578 https://news.ycombinator.com/item?id=12567578