Back
Nir Polak
Cofounder, Exabeam

Cybersecurity Leadership with Nir Polak of SignalFire and Exabeam: Empowering Security Teams

🎥 Jun 19, 2024 📺 GraceGong ⏱ 57m
With over 18 years of experience in the cybersecurity field, Nir Polak is a venture partner at SignalFire, a data-driven venture capital firm that invests in early-stage technology companies. Nir is also an investor and board member at Dig Security, a cloud-based security platform that automates threat detection and response. Additionally, Nir is the co-founder and chairman of the board at Exabeam, a leading provider of user and entity behavior analytics solutions. Nir has multiple skills in start-up environment, strategic partnerships, and start-ups, and Nir has a passion for building innovat...
Watch on YouTube

About Nir Polak

In a June 2024 interview, Nir Polak discussed the cybersecurity market and his views on the role of artificial intelligence in the field. Polak stated that "AI works really well when you have a lot of data and a large need for automation," and he identified security operations centers, endpoint security, and cloud security as areas where this intersection exists. He described the cybersecurity market as "roughly tens of billions" and said it breaks into submarkets including endpoint, network/firewall, security operations, and identity. Polak also noted that "enterprise sales cycles in security are long — typically six to nine months." Polak commented on the use of AI in both offensive and defensive contexts. He said that "protecting AI falls into two buckets: preventing data leakage from employees interacting with conversational models, and protecting your production AI from attacks like prompt injection." He also observed that "attackers are increasingly targeting non‑human identities — API keys and tokens — impersonating other systems rather than people." Reflecting on his experience at Exabeam, Polak said the company initially focused on "mid and large enterprises" and that "when you have a home run early you often incur a lot of technical debt."

Source: AI-verified profile updated from Nir Polak's recent appearances. Browse all interviews →

Transcript (55 segments)
G
Grace0:11
Just I have a full day, oh by the way, we're live. Yeah, I have a full day starting at 8, so that's kind of the only really whole. I okay, perfect. Okay, so hi Nir, welcome to Adventure with Grace. Hey, thank you. Great to have you be here. Okay, awesome. So to start off the show, I would love for the audience to get to know you a little bit more. So, you know, after the party at your house, I definitely researched you. I feel like you're extremely accomplished in the security space. You know, you started your career at Imperva and you quickly made it to VP of Corporate Strategy. Why don't we start there? Why don't we let the audience get to know you a little bit.
N
Nir Polak1:10
Of how I got into cyber, by chance. I'm not part of this 8200 unit that everybody's from. I was in a different fighting unit in the Army. But I got to Imperva while at college. I met the founder and CEO of Imperva, and I joined him on that journey. Techy by trade, my first day at Imperva was right after my last exam in college. I started doing QA and engineering and stuff, building product and testing the product. A couple years later, I moved back to Israel to run products for the company. One of the other co-founders left, and I replaced him to run products. I did that for about four years or so. Then at Imperva, we were filing our S1 to go public, and that's when I was tapped to figure out how to grow the company under the public eye. So that's how I did Corp. Every time I was moving back and forth both physically between Israel and the Bay Area, but also moving between a lot of different positions. I did many different things along the way at Imperva, which was great because it made me pretty knowledgeable.
G
Grace3:10
Since you were at the company for 10 years, when you joined, what were the jobs you were doing, maybe the technical things? Then later on you worked in product management, market strategy, and Corp Dev. I wonder throughout that journey, what was the core day-to-day you were doing since it was a startup and it was chaotic? I believe you said on another podcast that they were comparing this with war, but startup war is even longer. Can you describe a little bit more about the war, the day-to-day for running the business, and what were the things that you feel worked well?
N
Nir Polak4:12
Just testing software, running all kinds of manual tests on them, making sure that they're okay or not. In the beginning when I joined Imperva, there were no customers, it's kind of pre-revenue. We're talking about a very, very small organization. So there's nothing besides the product, so you're just building product and you have beta testing and customer testing and stuff like that. So that's kind of what I did. It wasn't as much of a fog of war for Imperva when it started, because when Imperva started, it's not like cyber today where it's much more of a... I would say when I started Exabeam, fast forward to 2013, the market is very different at that point. That was a very quick, meteoric type of climb. We started in 2013, I think 2015 was our first year selling, and we did like five million in change and like 30 different customers. It was very, very fast, and that is very fog of war. So you move from this vacuum of product and nothing in the beginning when you start a company, there's just building product and designing product and working... Actually, discover the client and then the client's needs and how does a sales cycle look like in the security space.
G
Grace6:10
So it's going to be different between Imperva and Exabeam.
N
Nir Polak6:27
So at Imperva, we sold web application security firewalls and database security firewalls, and nobody really knew what it was and what was needed when we started. It took a long time to get to sales, and then really the hockey stick effect happened when regulation started pushing the need for you to protect your applications, like PCI and Sarbanes-Oxley. Those types of regulations... That screen, we kind of connect all the different signals from everything that you've deployed in your organization and try to tell you if there's any alerts or anything happening in your environment. And there it was different. We told folks, look, your IT and your environments are very complicated, very difficult. You don't really understand what you're seeing. You don't even know what to ask for, what looks weird or doesn't look weird. We'll put this, quote unquote, magic brain or kind of machine learning AI brain, and we're going to slap it on top of your data and we're going to show you interesting things that you haven't seen before. And that was kind of the proof was in the pudding to show... Asking, and so that was a very easy sell. Technology is very difficult, but the value proposition was very easy. We went to a customer and said, hey, point us to your data, you're running Splunk or whatever that is, and we'll run on top of it and show you our findings.
G
Grace8:10
I wonder, so when you first started the product, was it the same as when it became what it is today? And how do you do the product improvement each time?
N
Nir Polak8:45
Yeah, so the product remained the same for a long time until the company had to rewrite everything for cloud native. So from the mockups we created in the beginning to the product, it was one-to-one, stayed on the same kind of track. There's good and bad that comes with that. When you have a home run on the first try and things are moving super, super quick, you incur a lot of tech debt, a ton of tech debt, and mistakes that you've made that now are cemented inside your architecture and your products and everything. So we had a lot of that. We got so many customers in the beginning of selling that we started building more and more features, and we had a lot of tech debt.
G
Grace10:11
Then it comes down to it. I know that looking at what you guys have on the website, you have a lot of great clients like Under Armour, just a lot of clients in different sectors in general, airline companies and everything. So when you first started selling your product, go to market, would you say you would start with a bigger brand or would you go after whoever will use your product? And how does the money flow in the security space that you feel like your product has a good chance of becoming a billion dollar company?
N
Nir Polak11:10
Company that has less than 2,000 employees, if I recall, that reach. And we did, you talk about Under Armour as an example, that was our first paying customer. Oh wow, way back in the day. I think they bought in 2014. But in cyber, it is one of these unique markets where you are selling to serious enterprises out of the gate. There is a very big need for innovation for the buyers to combat new threats, be able to solve their solutions. As a new company, you know how much money is spent in the markets that you play in. Exabeam was playing in the SIEM space or security operations space, and that is a three to four billion dollar market. So there's a lot of dollars in that space, so it's a given that you can build a long-term sustaining company with that.
G
Grace12:36
I have another question on that. Since you worked at another security company before, I'm sure you have the credibility, but since you're also a venture partner at SignalFire and you do a lot of angel investing, I wonder... Since maybe just add AI to it, right now there's so many voice fraud or visual fraud, like for example a family member calling you asking for money kind of stuff. I wonder if that's a really popular space. I see a lot of startups building the voice and visual fraud kind of things. So for that kind of things to work, what do you identify as a core thing that you would even look at? Would it be the technology, would it be the team? Obviously everyone says the team, but what does the team even mean? Do you feel like the veteran from a big firm like you would have a better chance to win?
N
Nir Polak14:10
Your other podcast, at the beginning I thought you were fully a technical engineer like coding mode or hacker mode, but when I listen to the other podcast, I feel like you're a very business savvy person, a technical storyteller kind of person. I wonder how do you examine if a startup would actually have the chops to win a market like this? Yeah, so I'll start with there's a difference between consumer plays to sell to a consumer, to sell to a B2B app, and to sell to security. Security is a niche inside enterprise. So when you talk about the team, typically the teams that will win are not straight out of college. They are not these youngsters. They are folks that do have commercial expertise. So if you look at a team, you're looking at a whole team. At least you need two sides: one that is a very good product leader that can also be a technical founder that is able to build the technical chops of that org around that. So that's the minimum you need. Now it depends on the product they're trying to solve. Sometimes the tech chops are super difficult and you need a technical god that can do it, and sometimes that's not the case. But for sure, if you look at all the successful companies in cyber, you will see that their product founders were super strong. I think that makes a huge difference.
G
Grace17:10
Do you identify yourself as a product person or are you more of the go-to-market person? How do you identify what is your advantage versus your co-founder or other people on your team?
N
Nir Polak17:20
Yeah, I am a product person. Am I a very strong product person? I'm okay. There are others that are way better than me that I've met along the years.
G
Grace17:38
You're very humble.
N
Nir Polak17:39
No, you just get a chance to work with a lot of really good people and you just beat them. There's just a lot of really good talent out there. So what makes a good product person, especially in the... opportunity to build a solution around that problem and how to stage that opportunity, where do you start from, how do you grow, how do you... I think really good product leaders are able to stare at a problem and figure out how to build a solution around it. This takes a long time, the process. It's not all in their head, but they're talking to a lot of people, customers, market experts, and they're trying to get a point of view on the market, and then they understand how to build a solution around it. There's a lot of examples of amazing products out there that have been built along the... and McAfee of the world, just by making the deployment super simple. That's a really good product that was built. I think if you look at the modern now with AI and data, I think companies like Glean that are building the ability to look at data and ask data and kind of corporate knowledge, those are amazing products being built.
G
Grace19:39
Totally. I wonder, since you are also investing in the space, where would you identify things that are interesting to you in cyber? A lot of things are interesting to me in cyber. For example, you mentioned when you started your company, it's a three to four billion dollar market. How did you, when you were first pitching to investors 10 years ago, how did you think about capturing a big chunk of the market? In general, how does the money flow in the industry, and where do you feel the opportunities are extremely exciting with maybe some big wave through AI or some other technical?
N
Nir Polak20:48
Sure. So cyber is a very large market. You have submarkets. One is what is known as the endpoint market. That's your old school antivirus, but now it's called endpoint protection. That's where CrowdStrike plays and SentinelOne and all that. That's a very large market. The second one is what was called the network security market, now it's called SASE or Secure Edge. That's where the firewall and Palo Alto and the likes started from, and that's a very large market. The third market is the security operations market. That's being able to connect all the different systems together and help the detection and response... Armbar and what you can access and how. That's a couple of billion dollar market, has a lot of services in it, a large market. So AI as a capability today, we're going to see new companies come up where AI is at its core. There's a bit of a difference where an existing company now starts putting AI in its products and bolting it on in different places, so you have a co-pilot and other capabilities, versus a company that was built in the age of AI and embraces AI, and AI is at its core. That's very different in terms of where the capabilities exist. So there's a lot of interesting companies being built trying to go after larger companies. These are different entrepreneurs that have built first or second generation products in the market and now are going to redo that for the age of AI. Those are very interesting opportunities because those are opportunities where you can displace a very big market.
G
Grace23:47
I wonder, when it comes to selling to different companies, for example, how does the sales cycle look like for a successful security company to close a deal?
N
Nir Polak24:17
Yeah, it is pretty long. It's an enterprise sales cycle, so you are looking at somewhere between six and nine months on average for a deal. So if I would look at the most successful companies, it's also a matter of what is their average contract value. Companies that are able to close easily... Enterprise, so this is not PLG where you just eat it up. It's a very top-down type of sale.
G
Grace25:17
So I wonder, when they actually... So basically you're saying in the space, in a certain space, it really needs people with a lot of experience within the security space and the network kind of to go with it. But when, since there's a lot of people who worked at really top security companies, I'm sure even for your company there must be people coming out of your company to do another company. How do you filter out who would actually have a shot?
N
Nir Polak26:10
Difference between a zero to one and growing. It's not the same typecast. So I think you have a typecast of people that love building something from nothing, and then you have the typecast of folks that like scaling something or perfecting something. But if I look at what would make them successful, one is their ability to think outside the box and take a problem and break it down into smaller problems. The second one is, as you're saying, revenue is very important, especially in a very competitive market like cyber. For cyber, with your product, it's super important, and understanding what value proposition you need to provide to your customer, what's the minimum viable product in order for you to sell, and how do you wow them. I think that if you have a combination of a very good product with a quick time to value, and associated with that a high ACV, that's how companies move very quickly.
G
Grace27:42
In terms of AI-related things, when it comes to the technology itself, where do you see as the major change between an AI-driven security startup and...?
N
Nir Polak28:11
You're leveraging AI. AI works really good when you have a lot of data and a lot of need for automation. That's the combo you're looking for. So markets that work with a lot of data and need a lot of automation is where AI can play a very big difference at that intersection. So I think in security operation centers, there's a lot of data. In endpoint, there's a lot of data. In automation, in cloud security, there's a lot of places where you have an intersection of a tremendous amount of data and a big need to automate decisions within... fell under this spectrum.
G
Grace29:12
So that's the other part of AI you were talking about, leveraging AI to improve your... so then you're protecting AI.
N
Nir Polak29:21
Yeah, so now that you have protect, protecting AI falls today in two buckets. The first bucket is protecting the interaction of your people, your employees, with a conversational model. Making sure that they're not sending any sensitive information outside. That's one type. You probably use ChatGPT every day, I do, and you send stuff. So when you're in an organization, are you sending sensitive stuff to ChatGPT? Making sure that none of that goes... or what was called CASB in the space. A lot of acronyms in cyber. The second is protecting your production AI. So you are now building a capability in your product where it interacts with AI, and then there's all kinds of different attacks. The biggest and well-known one is called prompt injection, where you're playing with the prompt and trying to make it give you some sort of personal information or sensitive information. There are companies being built around trying to protect your own models and AIs, but this is all in the... commercializing it in their platforms, and it's going to take a while for it to adopt. It'll take a while for that to have standards and then have a very clear solution of how to protect those.
G
Grace31:12
I wonder in that space, how do you see? Can you describe a company that you have invested in that you feel like you found exciting, maybe from how you meet the founder to eventually you decide to pull the trigger to invest, and then how do you think about liquidity or exit out of that?
N
Nir Polak32:11
You think that's going to become a larger market, then de facto you're going to have liquidity options. So I would start with, this is one of my companies called Clutch, and I can talk about that. How do I get to it? So I always go to first principles. The idea is, when I started Exabeam in 2013, really what was the problem in the market, which still is but we've made big strides, is a lot of the attacks today are happening by compromising the workforce. Sending them phishing, social engineering, stuff like that, and stealing... You gave voice when somebody's calling you, or even Zoom bombing. I don't even know if I'm talking to Grace right now. No one's telling me this is Grace. This could be an AI of Grace and Grace is still sleeping. So there are companies being built to vet that. But what has happened today, if we think about modern enterprises, we use a lot of microservices and we use a lot of SaaS. Truly what we have is not people accessing systems, but other systems accessing systems. Even now as you and I are chatting, this is getting broadcast on our LinkedIn or that. That's all this system called StreamYard. These identities of systems talking to other systems, that's how there's hardly any control. By the way, when we registered here and we connected our systems with LinkedIn, what it did is it generated what's called a token. It's like the shared key that StreamYard and LinkedIn... If I by the way am able to get access to that key, and it's just a string, I can now access my LinkedIn and I can do things on my LinkedIn. But it's more than that. It's like everything we do. You build a product today, it works with Snowflake. How does your production system talk to Snowflake? It's some sort of shared secret again. If you look at a lot of the breaches that... impersonate a human, they're impersonating another system, and that's a huge attack surface. So that's kind of what Clutch is going after, trying to protect against these types of new threats. What will happen with it, I don't know for sure, but it's a large opportunity because this is a new attack surface that is becoming more and more popular by our adversaries.
G
Grace35:38
I wonder, can you describe a little bit more about how you meet the team? Obviously you play an important role as the funding investor. How do you think about where the team found you or how you found the team?
N
Nir Polak36:10
Yeah, do you see it? It's an opportunity, and through a lot of my homework, I spoke to a lot of people just to get a point of view. Because when you have an idea, it takes a long time, at least for me, to get it down to a ground, say okay, there's something here. That process takes a lot of time and a lot of conversation. A ton. It's not like a eureka moment in a second. It takes time to get there. As I was looking into it, I stumbled on the team that was looking around that same area, a very strong team. So it's through the premise of the idea that I met the team. And the team was a very seasoned... You have founded a successful company before. I wonder why didn't you build this thing yourself? Why not operate?
So yeah, I'll tell you what I've learned about me as a person. I love building companies. I don't necessarily love scaling companies. It's just not me. I'm not good at it, really, nor do I enjoy it that much. I really, if my passion is building companies, having an idea, and it's kind of artistic, and you start building your... it was nothing, and then at one point you were like 800 employees or whatever. It's not the same. I just love building it. So if I were operating it, it would put me on the same trajectory of building something longer term, and I just would prefer to have the ability to build multiple companies at once, which is what I love doing. So I much more have purpose and fulfillment through that versus just doing one and scaling it.
G
Grace38:46
I wonder, in terms of the seasoned team, were you hunting in some particular companies? Or like, security startups that are famous for engineers coming out of a particular startup and then building amazing things? How do you source the high quality deals in general?
N
Nir Polak39:25
In Israel and cyber, there's just a lot of talent. With the whole 8200 unit, it's just a bedrock for talent over there. So there's a lot of really good teams and a lot of very seasoned people, and folks that have moved from Israel to here. So you don't necessarily... incredible. And now the question is, is there a good wholesome team? So it's not just about one person, but the team itself is really good. And is there a product founder fit that sits there? So I don't know about deal flow, it just happens. But I'm a very strong believer in karma, and trying to help others, and just out of trying to do good, through that good things happen. So I don't know, I just get a lot of deal flow through that. It's kind of how that... select this particular team.
G
Grace41:11
You mentioned about the team being pretty wholesome. So it has to be one is kind of like what I do mostly is I'm still meeting teams in the ideation phase, so super early. So it has to be that the area of the ideation I found interesting, and I really love the team, and I feel that you can build a large company here around that vicinity of an idea. So that's kind of how it goes. What would you say are making... knows how to find target, I'm talking about the Army, how to find talent and build that talent and give it really great tools and stretch the talent. I think for better or worse, it's just the result of what the Israeli Army did, created a tremendous amount of a vibrant innovation center. Then these people come out when they're really young, still in their early... and spend a couple of years in the commercial environment, learning how not to do it in an army but how to do it to sell to other enterprises and how commercial products look like. Then they have the itch to go and try to build something themselves.
I wonder, what does a build talent model look like? You mentioned the Army built talent, and there's tools, and they also like talent. What is a training program look like? Would it be like, here's a Stanford online university, learn this, or how does it work?
N
Nir Polak44:11
What I've seen and how I'm told that these things work is you look for highly intellectual people, highly inquisitive people, and you look for people that think outside the box. The way you do it is a lot of different tests, tons of them, and a lot of interviews. It is a system that is well funded that goes and hunts these kids when they're in high school and marks them. It's a well-oiled machine. The opposite, it was as if Stanford would go and hunt for applicants. It sounds like the Thiel Fellowship, it could be, but I don't know. It's a very concentrated outbound effort to be able to go through very rigorous testing. You're not accepted by your GPA plus your after-school curriculum. Nobody cares about any of that. They don't care about your grades. They just care how smart and how outside the box you can think.
G
Grace45:50
That's really... hack things, how to break things, how to do the talent you're looking for. Now you just need, you're looking for these beasts, and now it's about taming these beasts. How do you tame the beast? It's a system, but you know, it's what you find. How do you tame the beast? You just put it in control. You give it interesting things to break, and they like doing that.
N
Nir Polak46:46
I wonder, so finding the raw talent and then building, helping find these really thinking outside of the box... world, like they're able to sell to a lot of these Fortune 500 CISOs without any connections. How does that happen? Obviously they're also outside the box thinkers, but is there a training program for people? Number one, what does the environment have to be like for them to sell to these companies versus just build a really cool product?
Yeah, so there's two elements. One is the commercial nature. That's why we said teams that come out of the army directly are not good teams typically. They need maybe you... fit that. You're building the second is you need access to market. You need to be able to have very early conversations while you're still ideating with top Chief Information Security Officers of these enterprises. That's what a lot of venture does. It has a large network of CISOs that they work with to be able to validate ideas, pitch ideas, hone in on the product-market fit, and that's how it happens very quickly. So we were here, you were at my house for a team8 event. They just have team8 right now as we speak, or having their CISO... know their companies. When they have an idea or thinking, they're working with their CISOs to try to validate the idea and then find early adopters that are willing to purchase these early stage solutions. So that's how it happens. It's a lot through the venture capital that is connecting between the teams and the potential buyers.
G
Grace49:39
I wonder, since you are also a venture partner at a VC firm, how do you... how often do people sign their portfolio companies to the... like what, even selling to the CISOs after a quick conversation at a party with a CISO, how do we follow up? How does the conversation actually happen? Is there a more junior level person on the team that the people would have to sell it to, or does it just have to be the CISO to have the go-ahead of talking to?
N
Nir Polak50:40
Yeah, for sure. So a couple questions. One is, you can't burn these people because they have a day job, and they like staying in touch with the market and seeing new ideas and direction. So that's kind of... budget, but not the decision. The decision is made by the teams. So when you have a new company that is pitching to an enterprise, it will meet with the CISO, but very quick meet with the team. There's going to be a champion on the team, a couple of notches below the CISO, that is going to be the one to be a yay or nay. Then it's going to be a team, more than one person, and the decision is made, and the funding needs to happen through the CISO.
G
Grace51:53
I totally get that. When it comes to identifying the comm, as you mention the CISO approach, which is like the Israeli Army has a really great bench of talent. Since we live in Silicon Valley now, what would be the Silicon Valley equivalent opportunity for the younger talent or the people who are building in the security space but they're just generally without a lot of seasoned professionals? What are the opportunities for them? If you're building out a career in the security space and investing, without... more like it's still very fast growing and there's a lot of problems to be solved. How do you identify the opportunities for the more junior people in the space in general?
N
Nir Polak53:22
Yeah, I think that people need to be inquisitive. I don't think that when you come out of university or something, your first goal needs to be I want to go and build a new company now. I think your goal needs to be I want to go and learn, I want to get exposed. Maybe I'm just looking at me. I never knew what I wanted to do. I just kind of went with the flow and I grew with it, and I was very... necessarily be successful or not, but the ability for them to do many things and get exposed is really good. The second is finding mentors, people that are ahead of them in their career that they want to aspire to be, and just learn from and keep close to. So I don't think it's about did you work for a successful company, it's did you do interesting things, did you build interesting things, and did you gather experience, and then continue to do that. So that's what I would suggest. I don't think it's that important if you're going to company X or Y. Where you can do a lot of things and learn and get exposed to a lot of things, then you also have opportunities to grow. So that's my two cents.
G
Grace55:21
I wonder, when it comes to picking the small company to join, how do you join the ones that actually have legs to go a little bit further than if a startup will just fail in two years? But you're a young person at that point, you'll find another job if it fails. It's not that big of a problem. At least you got a really good experience in what you did in those two years. It's not like a C wedding when... time founders that have done something, people that have shown capabilities. But that's kind of like it. There's still a probability it will fail, and that's okay. Failure is part of learning, and you're just an employee trying to learn and grow. Through that, you've learned a lot, and you can understand if you're ready to do it by yourself or if you want to go and find another company to learn some more.
Okay, so we're at the last part of the interview. I want to be mindful of time. I know you have something at 8. I want to end with a one-minute fire round. First question, what's your...?
N
Nir Polak57:10
The it's a lot, but I don't necessarily read a lot of security stuff alone, a lot of business too. So I think The Information is a great publication.
G
Grace57:20
Who would you invite to your dinner party?
N
Nir Polak57:24
All my friends.
G
Grace57:27
Who made the biggest impact in your career?
N
Nir Polak57:31
My mentor, a guy named Shlomo Kramer.
G
Grace57:35
Where can we find you outside of work?
N
Nir Polak57:39
Flying planes.
G
Grace57:42
Oh, wow. That sounds like a really fun hobby. Anyway, Nir, thank you so much for coming on the show today.
N
Nir Polak57:47
Thank you. Thank you for having me.
G
Grace57:49
Let me quickly one second, let me...