BigID: Data Visibility & Control with CEO Dimitri Sirota

The MAD Podcast with Matt Turck · with Dimitri Sirota, Co-Founder and CEO, BigID

Dimitri Sirota is the Co-Founder and CEO at BigID. We cover why GDPR expands personal data far beyond traditional identifiers, how BigID uses scanners and graph ML to locate and correlate data across cloud and legacy systems, and why enterprise configurability can overwhelm smaller companies.

Watch on YouTube

Chapters

  1. 0:00 — Full episode

Transcript

Full episode

Matt Turck [0:42] Welcome.

Dimitri Sirota [0:43] Thank you for inviting me.

Matt Turck [0:49] All right, so let's start from the top. What is BigID? What does the company do?

Dimitri Sirota [1:15] Yeah, so we basically help organizations get visibility and control around their data. So you could think of us as a data security compliance company: next-generation, cloud-native, although we do support legacy data centers as well, where there's increasing push for reasons of privacy, security, even data governance, to know what data you have, what risky data you have, what valuable data you have. And that requires a way to look across, especially in the cloud, hundreds of possible varieties of data sets, from DocumentDBs to—I saw you're an investor in Cockroach—to everything that's possible in AWS, Azure, GCP, all the various SaaS applications.

Dimitri Sirota [1:58] And so there's a lot of complexity around knowing your data and then being able to do something around it, whether it's for reasons of privacy, regulatory compliance like GLBA, HIPAA, PCI, security in terms of remediating and protecting sensitive data, and then even data governance, being able to equip the data scientists with visibility into where their high-value data is as well.

Matt Turck [2:11] Both founders and investors like to think about, when they try to come up with a concept for a company, the why-now moment. What was the why now for BigID?

Dimitri Sirota [2:35] Yeah, so there hadn't been—look, I kind of always followed the space, and I was in New York, I'd sold a prior company, and I was kind of in a corporate development role, and I was kind of looking and talking to a variety of companies. Some wanted to get acquired, some we were targeting. So I had a reasonably good landscape, and I knew that I was only gonna be there until I got my green card. So part of me was thinking about what I wanted to do next.

Dimitri Sirota [3:05] And one of the things I observed is the data protection space hadn't really advanced very much in a generation. A lot of the tools, like the DLP tools, data loss prevention tools as an example, go back to the era of PCI. PCI, which stands for Payment Card Information, is a compliance requirement around payment card information, like your credit card numbers. And that was really kind of 2003, 2004. And so a lot of these tools originated to help organizations find credit cards, 16-digit numbers, in things that existed in 2004, right?

Dimitri Sirota [3:18] So that could be Exchange Server, that could be a file server from NetApp.

Matt Turck [3:18] Mm-hmm.

Dimitri Sirota [3:45] It could be a SQL Server from Oracle or Microsoft. And that was kind of like maybe SharePoint, but that's kind of it, right? And of course, the world has changed as companies have accelerated the move to the cloud, which has only gotten faster through COVID. They just have more complexity in terms of where data could be stored. There's more proliferation, more VCs like FirstMark are funding companies that provide applications and places where you can put data. So it's dispersing to more and more places.

Dimitri Sirota [4:17] Secondly, there's new regulations that are driving new requirements around compliance around that data. The one that got our attention was GDPR. And GDPR is a European privacy regulation. It came into effect in 2018, I think May 26th, if memory serves me correct, give or take a day. And it had certain requirements around data compliance. In particular, it said that companies need to provide transparency to consumers and employees around what data they collect and process on those individuals. And if you read the letter of the law, it requires them to know where every piece of your information is, not just your payment card data, not just your address, not just your name, but your IP address, your cookie, your session key, your credentials, your preferences, your clickstream history.

Dimitri Sirota [4:54] And that's a lot of data, and it could be kept in a lot of places. And we felt that the tools that were built in 2003 for Exchange and SharePoint and mainframe were not going to be the tools for the cloud to support this particular use case. And that was kind of the germination, the start of BigID. That was the big idea of BigID, if you will.

Matt Turck [5:09] And is a part of the complexity of GDPR that you need to be able to find all the data that relates to one individual in particular, as opposed to other forms of data privacy?

Dimitri Sirota [5:35] Yeah. So GDPR, and now today there are regulations in most countries. Canada has a new regulation. California had CCPA, which was replaced by CPRA. Virginia has a new law. Colorado has a new law. I think Washington State has a new law. Michigan, Ohio, Florida, Texas have new laws and committees. So again, it's getting more of a minefield. So under these regulations, consumers have a right to control their data, and that means being able to access their data.

Dimitri Sirota [6:07] It also means being able to delete their data. Technically, under these regulations, the definition of what is personal is very broad. Historically, when you look at breach regulations at a state level, the definition of personal data is very well defined, typically 13 or 12 attributes like address, name. Under GDPR, it could be anything, right? So my shopping preferences on Shopify could be personal data. My GPS coordinates. So right here, we all share a GPS coordinate, right?

Dimitri Sirota [6:31] We're all in the same location. That could be personal. What makes the problem hard, of being able to locate all of a person's data, is that obviously there could be a lot of things that define what is personal. In fact, instead of saying—and I'll talk about what we did that's innovative there in a second—but that's one thing, because it could be a very big universe. The way I describe it is: think of the old definitions of PII as kind of like the solar system, and then new definitions of PI, personal information, more broadly is like the Milky Way, right?

Dimitri Sirota [7:04] So much, much larger scale. Secondly, you have to be able to look everywhere because the people that wrote these regulations know nothing about what a CockroachDB is or what a SQL is or what a Mongo is. They don't know what any of these things mean. They're lawyers, they're legislators. So you need to be able to just look everywhere where data is stored. And the last thing, and maybe the hardest thing, is you needed to be able to correlate the data back to an identity correctly, right?

Dimitri Sirota [7:32] You don't want to confuse your data with my data. So we may share a GPS coordinate, but my instance of it is different than yours. And especially if I want mine deleted, you may not want yours deleted. So those three things represented a challenge. And so we used novel approaches for that kind of discoverability and actionability. We use graph ML techniques.

Matt Turck [7:42] Yes, let's get into that. So I'd love to understand sort of the architecture of the product. I mean, presumably you have a bunch of crawlers or connectors or whatever, like ways to get into the data.

Dimitri Sirota [8:07] Sure. So we started as a pure SaaS product. However, what we discovered early on is most of the companies that had this problem or cared about this problem were large enterprises. And back when we started selling—so we started selling at the beginning of 2018—the large enterprises were still a little bit schizophrenic around cloud. They didn't mind some of their ML kind of workloads in the cloud, but they didn't have their primary workloads in the cloud. And so we kind of split the product, the same product, but we essentially made it available, accessible on-prem or through kind of even a hybrid deployment.

Dimitri Sirota [8:36] So one thing to understand is, while we started cloud-native in AWS, we very quickly kind of realized that we needed to make the cloud runnable in GCP and Azure and in a private cloud, but also even in a legacy data center. So that's one thing we did. The rest of the stack, basically, we didn't want to go with agents because agents have complexity around instrumentation. There's some companies that have been successful with agents and sidecars, but we didn't want to do any of that.

Dimitri Sirota [9:04] We wanted to leverage the native protocol. What we do have is scanners. So we have kind of a two-tier architecture. We have a backend server, essentially. Think of it as kind of in the plain old telephone system, for those of you that remember it. There was kind of a switch in the headquarters of Verizon, I think, here, had a big tall building, and there was like a big switch underneath. So we have kind of like the brains that could sit in the cloud or basically in the company's, in the customer's data center.

Dimitri Sirota [9:35] And then there's scanners. And every instance of BigID, and you could have many instances, could have up to 100 scanners. Now, that orchestration of scanners obviously has complexity in that. How do you scale it up? How do you scale it down? You need a lot to potentially deal with very, very large workloads, petabytes of information, whether it's unstructured or structured. And the scanners essentially use native protocols. Now, they may differ. So, for instance, for Hadoop, we could do, like, MapReduce.

Dimitri Sirota [9:57] We could do direct connectivity to Hive or Spark we could use. But they all use native protocols to scan the underlying system. Now, we don't just do one kind of scanning. So the thing that I described early on, how we started, that was for privacy. That was our first use case, and honestly, the only thing we sold for two years. As we raised more money, and we raised, I think, I don't know, $250 million now, we expanded the methods that we support so that we could get into more data governance use cases, more security use cases, more compliance use cases.

Dimitri Sirota [10:33] But in the early days, when we did just privacy, we essentially relied on a training algorithm. So you would train the system on what is personal data for you. And that personal data could be in Chinese, it could be in Italian, it could be in French, it could be in English. So it was language-agnostic. And then from then on, once the system is trained, it basically runs itself and could look everywhere for an individual's data.

Matt Turck [10:46] So it's the scanner layer, on top of which you have the graph database layer, which establishes a relationship between the different parts. And then on top of that you have machine learning to extract patterns. Is that—

Dimitri Sirota [11:08] Yeah, that's kind of simplified. So we have the scanners, the backend, we have a graph. The scanners don't do this. Scanners kind of do parsing. They're kind of like dumb endpoints. Most of the orchestration is in the backend. That's also where we store the graph information. So we have a graph database embedded in the system. And we try not to keep data for regulatory reasons, privacy reasons.

Dimitri Sirota [11:35] So we essentially keep almost like a GPS. We keep pointers that are tokenized and salted, and then we have a little bit of encrypted metadata to make it searchable. So think of it as this kind of virtualized inventory of the data. It's searchable, but the data still stays in Snowflake and Databricks and in Hadoop, in SMB, NFS, CIFS, whatever that is.

Matt Turck [11:52] So I'd love to double-click on what you started talking about and understand the use cases. So privacy, what is a scenario for privacy and how does BigID help? And then maybe move to the other areas, governance.

Dimitri Sirota [12:08] Yeah, sure. So I'll kind of describe our evolution in kind of three steps. So I would still look—our tagline, if you go to our website, is, "Know your data, control your data." So kind of very similar to what I described around data visibility and control. What we focused on for the first kind of three, four years of our history is really just knowing your data and looking for applications of where do you need to know your data?

Dimitri Sirota [12:43] Why was it important? So first we settled on privacy, right? So I think we were six people when we sold our first enterprise customer, Nike. And I sold it from, like, the backyard in Mamaroneck, in Orienta, by the pool. I didn't even have a shirt on. And our second deal was Intel. And these were, like, meaty first deals. And it was, like, literally dialing for dollars. We didn't have any relationships. We didn't even have investors that had connections in these firms.

Dimitri Sirota [13:15] But we looked for kind of a repeatable use case. And the GDPR one was appealing because, A, the old technologies couldn't solve the problem. There was obviously a regulation over the horizon. It impacted large companies. They would have liability both in terms of the country regulators, the DPAs, potentially individuals. And so we focused on that use case. And so privacy, and in particular just this data access, data deletion use case, that's all we did. That's all we did for two years.

Dimitri Sirota [13:37] But what we found was something highly differentiated, and because of that, in our first full year, we did $5 million in revenue. And in our second full year, we did $15 million in revenue. And so that gave us the kind of springboard to raise more money. We struggled raising our seed money. We almost couldn't get it. But when we did start getting money, we kind of—I think it was our C round, which we got sometime mid-2019.

Dimitri Sirota [14:07] Or September of 2019, that we started first thinking, okay, what does know your data mean? How do we expand this from the single privacy use case into other regulatory, other security, and even data governance use cases? And so what we built is a set of four technologies for looking at your data. One focused on metadata, right, for the data governance, for the data science use case. So how do you extract and harvest metadata, label it automatically, do it at scale across structured, unstructured, semi-structured, being able to deal with billions of objects and tens, if not hundreds, of petabytes.

Dimitri Sirota [14:45] Secondly, we did data classification, leveraging natural language processing, deep learning, to be able to identify almost any kind of crown jewels, something of value, right? Because things of value also represent risk. So that could be maybe a recipe, that could be a patent, that could be an employee document, anything. And then lastly, we developed a technology to be able to profile data at scale. What that means is being able to not only gather statistics on that data, but look for duplicate, redundant data, understand dispersion, parts of lineage.

Dimitri Sirota [15:19] And so we developed each of these four technologies over a course of probably two years to give us an ability to address not just privacy, but security, data governance, and then lastly, kind of data lifecycle management, people that care about duplicate, redundant data. So there's kind of four use cases that drove that kind of know your data, and there we stopped. And after that, we added the control part. I don't know if you want me to continue or you want to ask another question.

Matt Turck [15:32] Yeah, I'm curious how that works from a go-to-market and sales perspective. Do you have presumably different buyers?

Dimitri Sirota [15:58] We have three audiences. Yeah. So I would say about 40, give or take, 40% of our business is the CISO organization, about 40% the CDO, maybe about 20% is privacy and compliance. Look, having more kind of at-bats never hurts. We don't have to sell all three. We could get a land before we expand in any one of those three organizations.

Matt Turck [16:00] What's your favorite land?

Dimitri Sirota [16:15] It's funny, it varies with who we have. Right now, we have a lot of sellers that come from the security world, and obviously, as the market gets a little bit more challenged in terms of sales cycle, security is a good place to be.

Matt Turck [16:16] They—

Dimitri Sirota [16:36] Their budgets tend to shrink the least. We do a lot of business with CDOs. The partner we were just meeting that I was coming from and having dinner with tonight, we had representation from privacy, we had representation from the data organization, and from the security organization, because it does impact the business. Look, every part of that business needs to know their data, and data is becoming the— I think as organizations go to the cloud or accelerate to the cloud, as they undergo digital transformation, if you will, depending if you're in old-school consulting and that's how you refer to it, there's all these new challenges. But on top of that, you have this issue that there's a high cost.

Dimitri Sirota [17:15] You're renting storage now. You're not capitalizing it with your NetApp and EMC server and so forth. So there's much more vigilance that's at play, both in terms of data lifecycle, in terms of data reduction, minimization. And so I think it's just becoming much more complicated. And also, I believe that when data was in New Jersey, in your data center, which was like where JPMorgan kept it and UBS and everybody else, people had this false sense of confidence that they knew kind of what was in there, right?

Dimitri Sirota [17:53] And that it was protected. They had a padlock on the door, they had some gatekeeper, maybe a security guard, and so it felt safe. Now that data is in the cloud and there's multiple stakeholders that have requirements around the data because auditors and regulators and boards want to know what's at risk and what's of value, I think it just becomes more complicated. So products like ours, I'd say we've done well. We'll cross $100 million this year, but I think it's just now— we're not in any marketing report.

Dimitri Sirota [18:23] There is no Forrester Wave or Gartner MQ, but there will be this year. We're now getting to a point where every big consulting shop is looking at a practice around this. The analysts recognize this as a precursor to— you can't do the control unless you know what you're controlling. You can't do access on something unless you know what it is. Am I going to put restrictions on accessing the data if I don't know what it is? So I think that's becoming of value.

Dimitri Sirota [18:49] The one last thing I'll just mention in terms of our evolution, though, is we realized just knowing your data and knowing you have a problem is not good enough. You need to be able to fix the problem or get more value from the data, either through reporting or whatever. And so we struggled for a while trying to think through, well, how would we do this? Are we going to just pick one like DLP or DAM or DRM or whatever, any acronym soup you want, or DSPM?

Dimitri Sirota [19:20] And we realized, why don't we borrow a page from the playbook of Microsoft and Amazon and Splunk and Apple iPhone and create a marketplace, a marketplace of apps that essentially allow you to layer on controls, both BigID controls as well as third-party controls, right, from Collibra, Atlassian, ServiceNow, and essentially create this kind of thriving ecosystem. So one of the things we did early, which is kind of a little bit unique for a company of our size, right? It took CrowdStrike a decade before embarking on their marketplace strategy, is in around mid-2020, we said, we can't really choose what control we want to layer.

Dimitri Sirota [19:56] So let's think through all the controls you can have around data privacy, data security, data governance. Some we'll build, but some we'll encourage other parties to provide. So, like, Collibra has a data stewardship module. ServiceNow has two, one for workflow and one for CMDB integration, bidirectional CMDB integration. We want one with Tableau. We have one with Snowflake around access control and masking. We have ones with all— Thales is building one or has built one.

Dimitri Sirota [20:23] They're an encryption company, but as well as Fortanix and others. So right now we have like 50 to 60 apps, about a dozen of them our own. And the nice thing is, is that it allows organizations to grow. So we could land with that kind of know-your-data. But then when it comes to access control, remediation, data minimization, data retention management, there's an app for that, as Apple would say.

Matt Turck [20:27] How far along were you when you started that marketplace?

Dimitri Sirota [20:52] It was a couple of years ago. So look, we had revenue, but I still think it was probably under 30. We benefited. I think we decided to do it after the Tiger money came in, so we had to spend the money on something. And back then, you just hired a lot of people. You don't do that anymore. But yeah, I think it basically came because we realized data is a massive problem, right? And historically, people kind of ignored it.

Dimitri Sirota [21:23] You had vendors that specialized in pockets of it, like Varonis, for those of you that are familiar with it, that focused just on unstructured data. So things in your SMB. You had Proofpoint that just focused on email. You had Symantec that did a little bit of unstructured but mostly structured. You had Collibra or their antecedents that focused on just extracting metadata from SQL databases. So it was kind of a hodgepodge. There was nobody that provided you universal visibility across the data.

Dimitri Sirota [21:56] And we think that's important to have a consistent set of rules, controls for, again, reporting on that data, whether it's to regulators or whether it's to board members or controls just around access. So that was kind of what we embarked on. I don't think we've reached our destination, but I think we've been able to kind of pull ahead in the space, so to speak. I'm not sure if that metaphor works, but you kind of get what I mean.

Matt Turck [22:06] That's very interesting. I mean, the idea of building a marketplace for companies is great. It's particularly hard to pull off, especially for younger companies. I was curious about—

Dimitri Sirota [22:27] We have a surprisingly good attach rate. Again, we always focus on that kind of know-your-data problem, that discoverability, that classification. It uses different terms, so data governance talks about it in terms of catalog, security talks about it in terms of classification, privacy or compliance talks about it around inventory of critical data. They may use slightly different terms, but that's always kind of our starting point. I think we benefit from the fact that if you're going to the cloud, you got to know what you have.

Dimitri Sirota [22:53] It's a little bit like moving houses, right? You don't want to take everything with you. So you got to go through, you got to rummage through your closets first to figure out what you're going to throw away or give to Salvation Army. And then once you're in the cloud, you want to kind of keep it nice and pristine as well, because again, you're paying for every gigabyte. But yeah, so we start that way and then the rest is an add-on.

Matt Turck [23:02] So still within the go-to-market part of the discussion, I'd love to rewind back to something that you said earlier about you selling from the pool without your shirt on.

Dimitri Sirota [23:04] Don't tell Nike.

Matt Turck [23:26] If you ask VCs, for what it's worth, a lot of people are going to say, well, if you're a tiny company selling to the Nikes of the world, it's super hard. Don't do it. Sell instead to startups or early adopters. How were you able to pull it off, and any lessons learned for people in the audience who might be early-stage entrepreneurs?

Dimitri Sirota [23:51] So look, there's a couple of things here. I'm going to be very honest. One is, the reality was the people that cared about our problem, that we built this beautiful mousetrap—well, we got to look for the people with the mice, the ones that had the problem most acutely and had the biggest penalty. The regulators in the UK or France, like CNIL, they're not going after Joe's Autobody. They don't care about Joe's Autobody. They're going after the multinationals.

Dimitri Sirota [24:13] So they had the problem. Secondly, it's also a matter of comfort zone, right? I was starting this company in my late 40s. I'm 52 right now. I'm sure you guys all think I'm 35. So I had sold to enterprises, and on top of that, I didn't know a lot of the CTOs at a lot of these startups that are 25 years old. I don't know them. I know the people that are CTOs at the bigger institutions.

Dimitri Sirota [24:39] They're more my age. I think there is also just a comfort zone in terms of who I was comfortable selling to. Today we do sell to SMBs, we sell to mid-market. I would not say SMBs, but obviously I don't do the selling, and we have a bunch of young people doing the talking to the younger. I do think there needs to be a compatibility, and it may sound terrible, but I do think there's a reality to it, right? You sell to who you're comfortable with.

Dimitri Sirota [24:55] And so again, we looked at who had the problem most acutely and had a penalty if they didn't do something. And then secondly, who would we be able to dialogue with and explain the problem to, and who would have the attention span to deal with us?

Matt Turck [25:07] As I was prepping for this, I also read that, if I understood correctly, you have a motion to go downmarket that very nicely you call SmallID.

Dimitri Sirota [25:08] SmallID. I came up with the name, everybody.

Matt Turck [25:20] That's very, very cool. And again, that's another sort of unconventional thing. You'll hear a lot of people saying, well, once you start selling to Global 2000, going downmarket is harder. How do you do it?

Dimitri Sirota [25:42] Yeah, look, and here's what I'll share with the entrepreneurs in the audience, having done both. If you start selling to SMBs, it's very, very hard. It may seem like, oh yeah, I'll just add more features and I'll go upscale. The reality is, when you sell to large enterprises, no two enterprises are the same. They're basically like snowflakes, right? Depending on the authentication that they use, whether it's Kubernetes or Kerberos or SAML or whatever, they all use password vaulting technologies like CyberArk and HashiCorp and BeyondTrust and Thycotic.

Dimitri Sirota [26:19] They all want role-based access control. So not just integration with your LDAP and AD, but the ability to scope down. So they have these enterprise requirements around reporting, around— and so I think it's hard for small companies because they haven't done that. They haven't sold to that. Sometimes they just came out of college. They don't know what RBAC is or why a company would care about that. They don't know why they need to integrate with password vaults, as an example.

Dimitri Sirota [26:46] Why don't they just give me the credentials? And so I do think it's hard to go from small to big because when you sell to a smaller company, they just want the easy button, right? They don't have the bandwidth. They don't have the resources. Now, having said that, it's also not trivial to go from big to small, right? Because one of the things you do for big is you make your solution highly configurable. So the Accentures, PwCs love that.

Dimitri Sirota [27:08] The big companies, they don't love it, but they need it because, again, no two are the same. But configurability can easily look like complexity in a smaller organization. They go, oh my God, overwhelming number of choices, lots of things I could choose from. It's like an Apollo mission, right? Lots of knobs to get to the moon. So we needed something that essentially eliminates the complexity, which is great for configurability, but something that provides more of an easy button.

Dimitri Sirota [27:39] Now there's certain assumptions, right? We're not going to support on-premise. If you have it, tough beans. You have to do automated discovery. We're only going to give you— we're not going to do RBAC because smaller companies don't really care. They have a CTO who's also the CISO who's also the CDO. They have one person in that seat. So SmallID is that. Now it's a journey. We did a soft rollout.

Dimitri Sirota [28:02] We have a little bit under $1 million in revenue. We started rolling it out around September. We learned some things. We also wanted to make it consumption so we could do our Snowflake thing. We're adding a few more things. Look, we have high hopes that that'll be our solution for smaller businesses, easier to understand, and it's a little bit self-selecting. I'm a small business, I go with small. We have clever phrasings: big things come in small packages, or small things like that.

Dimitri Sirota [28:11] Start small before you go big, et cetera. It creates an easy model.

Matt Turck [28:12] It's an easy model.

Dimitri Sirota [28:26] If you have complexity or if you want to graduate to something that requires a lot more configurability, different users of the product—BigID, under the hood, it's the same thing. It just has a very different user experience for it, and it's only available as SaaS.

Matt Turck [28:33] Great. And maybe to close before I open up to questions here, this is your third startup?

Dimitri Sirota [28:36] Yeah, look at me, look at my gray hair. Yeah, third startup.

Matt Turck [28:48] Yeah, at 35. I'd love to hear anything you can share, things that you wish you knew then that you know now.

Dimitri Sirota [29:08] I thought black swans— I remember, so I started my first company right around 2000, so we had the full kind of hurricane impact from the first kind of black swan event. And they told me this was going to be kind of once a career, and I think I'm on my fourth now. So, look, I think that's challenging. I do think so much of this is situational, right? There are times when I thought, oh, wouldn't it be great to just sell to other startups, right?

Dimitri Sirota [29:38] Like what you're just describing. Some of those companies are able to just get a huge amount of traction really early by selling to friends, selling to connections to the VCs. But then when something like this happens, good luck selling to another startup today. They're trying to rationalize all of their tools. We are doing it. And it's much better to be selling to enterprises and selling to security. So again, depending on my mood and day, I'd say, oh, wouldn't it be great to sell to small companies?

Dimitri Sirota [30:06] Today, I'm pretty happy we're selling to enterprises. The sales cycle may be a bit longer. There's more complexity. But at least there's more stability in those buyers, especially when you have this kind of my fourth black swan, if you include 2020 and then 2008 and then 2001. So there's that. Look, I wish I knew then what I know now in terms of raising money, in terms of public speaking. I do think it's very important to be able to tell a story, right?

Dimitri Sirota [30:31] The reason I was able to sell Nike, I think we only visited them once before they gave us a check for $400,000. We told them we're six people. They had no illusions about how big we were over Zoom. But I do think it's important to be able to tell a story, right? That narration is huge. It's big if you're writing fiction. It's important if you're starting a company. So I think I didn't really know that in my first company, not even in my second.

Dimitri Sirota [30:54] We did API security, which today is a big topic. Back then, nobody knew what an API was. So it was a little bit like wandering the desert. So I also think that there's a timing. The other thing that I kind of have learned is, and I do still hope to have a fourth company, so we'll see if I don't keel over before then, I think one thing I've learned is when I did my first two companies, I kind of did blue ocean-type stuff, right?

Dimitri Sirota [31:24] This is a new problem, a new concept. That's really hard because market timing is everything, right? And like I said, my second company, we started talking about API security and management in 2003. Nobody knew what the hell an API was. They couldn't even spell API until really Amazon Web Services came out, mobile applications took off. So you're really looking at 2009, 2010. So when we did this company, we said, okay, there needs to be a tailwind.

Dimitri Sirota [31:54] There needs to be some kind of propellant or catalyst. So we looked for a regulation, right? There are budget dollars set aside for GDPR. And if we get a portion of them, look, we just need to get $1 million. $5 million was kind of even better, but that was kind of a catalyst. So I think looking for that catalyst. The other thing I would probably do for my next company is something where there's an already established spend. Privacy was still a new category.

Dimitri Sirota [32:15] Yes, there was money because of the regulation, but as you know from Snowflake and anywhere where you may already have data warehousing dollars and you're just creating a better solution, or CrowdStrike where there's endpoint security budget set aside for McAfee and Symantec, and you could just take money. And I think that's more important now, especially during a downturn, is hugely important.

Dimitri Sirota [32:39] So look for a catalyst like a regulation if you can, but also look for an opportunity where, again, there's something that, if they use your product, they're going to be able to save some money by replacing something else.

Matt Turck [32:44] All right, very cool. On this note, thank you so much. Really appreciate it.

Dimitri Sirota [33:13] Thank you, everybody. Thanks, Matt. Thank you. Thanks for joining us for The MAD Podcast. We're back here every Wednesday with new conversations with leaders in the machine learning, AI, and data space. And if you like this show, you can also find a video recording of not only this episode, but many, many more over on the Data Driven NYC YouTube channel. Thanks again, and catch you next week.