Showing posts with label SaaS. Show all posts
Showing posts with label SaaS. Show all posts

Tuesday, March 29, 2022

Your cloud data needs a reality check: our investment in Cyera

 

Yotam Segev (left) and Tamar Bar-Ilan (right), cofounders of Cyera


The complex equation of data reality


With AWS, Azure and GCP growing 40-50% YoY at massive scale (AWS’ run rate is more than $70B!), it’s fair to say that migration to the cloud is in full swing. That said, some large sectors like financial services and healthcare only started to migrate their core workloads and data to the cloud more recently. With less than a third of workloads currently migrated, there’s still a long way to go*.

 

One of the benefits of the cloud is that it gives development teams more agility and flexibility, but with increased flexibility comes the downside of a loss of control and visibility. This is a particularly acute issue for data, which is the most valuable and sensitive asset of many businesses.

 

On top of the move to the cloud, the volume of data continues to grow exponentially. Latest estimates are that the 65 zettabytes (1 zettabyte = 1 billion terabytes) of global data in 2020 will have nearly tripled by 2025**. With digital transformation accelerating and new AI based applications being created and perfected every day, this growth isn’t set to stop anytime soon. Add to this the constantly increasing compliance and privacy needs, including GDPR and CCPA, and the growth of cyber threats, and you end up with the following equation:

 

Data reality: 
cloud migration x growing data sets x increased compliance x cyber-attacks 
= big headache for CTOs and CISOs


So how do you solve this equation? You have to eliminate the headache. 


Cloud security and compliance stack


We think about cloud security and compliance in four distinct layers:

  1. Infrastructure layer: securing your cloud infra typically requires a CSPM solution (cloud security posture management – a tool identifying misconfiguration issues and compliance risks for your cloud infrastructure)
  2. Identity layer: who can access what, typically managed by an identity management layer
  3. Application layer: organisations now are increasingly applying the “shift left” principle, giving developers the tools they need to write secure code, instead of relying on security teams
  4. Data layer: understanding where your sensitive data is and what policies should be applied in order to ensure that it’s safe and compliant

 


 

Over the past few weeks, we’ve talked to many CISOs and CTOs about cloud security and here’s what we observed:

 

  • Regardless of whether companies are cloud-first or in the process of moving their infrastructure to the cloud, understanding and securing their infrastructure is a key priority for CISOs/CTOs. The fact that it’s so easy for employees to create cloud resources and move them around is creating “infrastructure chaos” and driving an acute visibility issue
  • Most companies we spoke to already had a CSPM solution in place. Ease of set-up was a key adoption driver for these solutions
  • The identity layer was well addressed and understood via solutions like Okta
  • While several companies had heard of the shift left and were already deploying Snyk, others were just starting to think about it. It seems like we’re at the early inflection point of the S-curve on this front and expect the momentum to continue - and even accelerate - as large companies expand their deployments to all their development teams
  • When it comes to the data layer, all companies are lacking visibility on what sensitive data they are collecting, where it's stored and whether it's at risk. The situation is untenable, leading all companies we spoke to have put cloud data security on their list of priorities for this year. Many were starting to search for a dedicated solution for the cloud data and compliance layer


Cyera: solving the data reality equation


Why is the data layer challenging to address when data security has been an established field of cyber security for such a long time?

 

The issue is that existing products focus on endpoints and on-premise datastores. Sub-categories include DLP (e.g. Code42, Digital Guardian), data privacy (BigID, Privacera), encryption (Enveil, Protegrity) and data security platforms (Ionic, Varonis). Many of these products rely on an agent-centric architecture which must be installed on each endpoint in order to monitor data. With the shift to cloud, a more scalable architecture is possible - and indeed required - to deal with the scale and dispersion of enterprise data. These solutions weren’t architected for the cloud at inception and don’t have the simplicity of deployment and functionality expected by cloud users. In addition to the data security pure-plays, the cloud service providers also have some data security offerings for their own clouds, including AWS Macie, but these fail to support the multi-cloud architectures favoured by most large enterprises and are also expensive to run while also not providing full coverage of the data landscape. In the case of AWS Macie for example, only S3 buckets are analysed, leaving significant risk across enterprises’ complex data environments.

 

The failure of existing data security solutions to address cloud specific issues are reflected by the increasing numbers of data breaches that are increasingly sophisticated and targeted. CrowdStrike recently reported an 82% increase in ransomware-related data leaks in 2021. There is no industry or scale of enterprise which is immune from the threat of exposing sensitive data records.

 


 

We concluded it was time for a cloud native data security platform, identifying the key success factors as:

  1. Platform: buyers are looking for a platform that includes discovery, accurate classification, risk assessment and remediation
  2. Ease of deployment: cloud buyers expect a “plug and play” solution with very short time to value (hours/days rather than weeks)
  3. Cost efficiency: the technical challenge will be to infer the key risks from data and metadata while being smart in the scope and frequency of the scans at enterprise scale to be cost efficient

When we met Cyera, we knew that we’d found the perfect team to address this new category of security. We loved the passion, drive and ambition of Yotam and Tamar, Cyera’s two founders, and could see that the data and security background from their service in the Israeli military uniquely equipped them to address this massive opportunity. With the elite initial team they’ve assembled, they’ve managed to build their first product in record time and secure large six-figure deals while still in stealth mode. Cyera’s technology is the first time we’ve seen a data solution that has such quick time to value, full coverage, and ease of deployment and it explains why the CIOs and CISOs we spoke to immediately asked us for an introduction to the company.

 

We’re excited to announce today that we’re co-leading a $60M round with Sequoia and Cyberstarts in the company and look forward to working closely with Yotam, Tamar and the whole Cyera team to build the leading cloud data reality platform. Thank you Yotam and Tamar for choosing to partner with us!

 

___________________

 

* See Accel 2020 Euroscape

 

** See Statista

Monday, March 28, 2022

Accel 2021 Euroscape: On the path to global dominance?

 


The Accel 2021 Euroscape was unveiled earlier today at SaaStock EMEA and you can view the full presentation here.


*************************


The European and Israeli cloud ecosystem is accelerating as never before.


Back in 2016, Europe and Israel had only four public companies worth less than $9B combined and local cloud companies had raised just $900M throughout 2015. Today, Europe and Israel have generated 23 public companies worth $231B and private cloud financing reached c. $30B. The $900M of SaaS VC funding in 2015 now represents less than Europe's largest financing round, with Celonis raising $1B in June this year.


And the milestones don’t stop there: 

  • Europe generated the largest cloud IPO of 2021, with UiPath closing its first day of trading with a $36B market cap
  • Europe and Israel minted the two fastest cloud companies to hit unicorn status, with Wiz (14 months) and Hopin (17 months)


So now feels like the right time to ask: “Are Europe and Israel on the path to global dominance?” 





Before answering this, let’s take a look at what happened in the global software and cloud market over the last year.


Global market snapshot

The world now has 10 software and cloud giants worth more than $100B, representing $4.1T of market capitalization. This world of giants is dominated by one colossus: Microsoft. The company weighs in at more than half (55%) of the entire group and grew its market cap by $600B+ - more than the nine other companies combined! In 2014, when Satya Nadella succeeded Steve Ballmer and became CEO, Microsoft was worth $330B. The development of Azure and the shift to the cloud has propelled the company to new heights. 


Looking at newcomers, this year has seen two companies break the $100B market cap mark: ServiceNow and Square, pushed by the rise of enterprise automation and digital payments respectively. One of the 2020 giants also left this select club: Zoom, which was impacted by the failed acquisition of Five9 and people’s gradual return to offices.




Beyond the giants, the momentum continues for the public companies in our global cloud Index. The Index added another $0.9T in value in the past year and the pace of growth is accelerating. The average growth rate of the companies increased from 18% last year to 26% this year. While the average forward revenue multiple has declined slightly since its February 2020 peak (19x), it’s still higher today than last year at 17x vs 15.8x in Sept 2020.


The cloud IPO market has also been very active with 32 IPOs vs. 17 in 2020. It’s worth noting though that while the number of IPOs increased, the companies were smaller and raised less capital than those last year. In 2020, c. 60% of the cloud IPOs had a market cap of $5B+ vs. only 28% this year. As the IPO window was pushed wide open and multiples reached new highs, the public market tempted smaller companies while the 2020 crop was more mature. The beginning of the year also saw a lot of hype around SPACs, but few cloud companies chose this route to go public (only 11 in Europe, Israel and the US in 2021) and their average market cap was on average less than half of the IPOs. 


On the M&A front, while 2021 has seen one of the largest ever cloud acquisitions - Salesforce’s acquisition of Slack for $28B - the year’s top three strategic M&As (Slack, Mailchimp, Auth0) represent only $47B. This number looks relatively low compared to $330B+ of cash and cash equivalents sitting on the balance sheet of the cloud giants and public companies in our global cloud Index. It seems that the high multiples we’re seeing on the private markets are deterring public companies from actioning some M&As but we should expect this dry powder to be put to work at some point, if the multiples are correct.


Private is the new Public


The private cloud financing market is firing on all cylinders. While last year was a record-breaking year, 2020 now looks small in comparison to 2021 to date. Private cloud companies in the US, Europe and Israel have raised a whopping $78B YTD. Annualised, this would be 2.7x larger than last year! The number of unicorns has also nearly doubled from 131 to 226. The pace of innovation we’re seeing in the cloud ecosystem is unprecedented, driven by the continued shift to cloud infrastructure, the need for more automation to support digital transformation, increasing security challenges and the growing amount of data to be managed and leveraged for insights and machine learning.


What’s even more remarkable is that the amount of financing poured into private cloud companies dwarfed the amount raised by public cloud companies in 2021, as hedge funds like Coatue, Tiger and Dragoneer are turning their eyes to the  private tech markets. 




Europe and Israel ecosystem reaching escape velocity

While the global cloud market is growing fast, Europe and Israel are accelerating even faster. Leveraging 20+ hubs across the region, an unparalleled level of entrepreneurial talent and ambition, and full access to global capital markets, European and Israeli cloud start-ups no longer have to envy their US counterparts. And the numbers speak for themselves. In the past 12 months, Europe and Israel have generated 11 new IPOs vs. 3 in 2020 and the total market cap of public Europe and Israeli cloud companies has reached $231bn, up more than 2x from last year. These 11 new public companies have raised a total of $6B, including three monster IPOs which account for 55% of this amount (UiPath, SentineOne and Monday.com).


On the private side, the magnitude of the growth is also unprecedented with c. $30B raised by Europe and Israel’s private cloud companies, a 3x jump from last year. This influx of capital has pushed the number of unicorns up from 44 companies in 2020 to 81 companies this year. With financing rounds now reaching several hundred million, these new unicorns now have firepower that private companies have never had before. This money is actively invested in product - with roadmaps fast-expanding - and M&As, with unicorns acquiring products and talent across regions. For example, Snyk has recently announced a number of acquisitions. This increased ambition and footprint is recognised by investors, as 14 of these unicorns are now valued at more than $5B vs. just two in 2020. 




These 81 cloud unicorns have a combined value of $234bn, which is close to the $231bn of their public counterparts, pointing towards a promising IPO pipeline for the next couple of years.


Looking more closely at the region, Israel is undeniably emerging as a cloud unicorn factory, with 16 new unicorns in 2021 (around a third of the total minted this year to date). Israel also has the largest number of unicorns per capita, with 2.9 unicorns per million people, which is significantly larger than the 0.1 - 0.3 in other major hubs (France, UK, Germany). The key to Israel’s cloud success is due to a number of factors, including:

  • Incredible talent coming from its military intelligence unit 8200 and local offices of large tech companies (developed through historical M&As)
  • Expertise in areas supported by secular trends: cloud security, infrastructure and payments
  • A dense network of seed funds poised to invest large amounts at a pre-product stage ($5-10m)
  • Access to global capital at growth stage

Are Europe and Israel on the path to global cloud dominance?

Going back to the question we posed at that start, our answer is: yes, the gap that has long existed between European and Israeli SaaS companies and their US counterparts is now closing. All of the data points to the fact that Europe and Israel are on the path to be as fertile as the US - and potentially even more - in the coming years. In terms of the public company figures, there may have been fewer IPOs from European and Israeli companies (11) compared to the US (21), but the metrics are comparable:




And it’s a similar situation when it comes to the region’s cloud unicorns:





Similarly, while the US continues to lead when it comes to private cloud funding volume ($48bn vs $29bn), the rate of growth year-on-year is higher in Europe and Israel (3.2x vs US’ 2.4x). Will we see the gap completely close over the next 12-24 months? We’ll have to see what next year’s data reveals, but what’s certainly become clear over the past year is that the cloud world is a very different one from the one we mapped back in 2016.


The world of cloud is now flat

At the end of the day, which region attracts the largest amount of capital isn’t the most important point. What matters most is that innovation in the cloud can now come from anywhere. Accel has been a big believer in cloud since the early days of this shift. The firm was founded more than 35 years ago and the team quickly realised that innovation was not confined to Silicon Valley. We opened our office in London in 2000, followed a few years later by Bangalore. To date, we’ve invested $7B+ in more than 300 companies globally and have worked with many exceptional cloud founders - from Australia to India, the US, Europe and Israel. It’s inspiring to see that the world of cloud is now flat and any region can generate a category defining company, from Atlassian in Australia to UiPath in Romania, Celonis in Germany, Snyk in Israel, and Docusign and Crowdstrike in the US.



What’s next?

Looking ahead to what 2022 may hold, there are six key trends we see accelerating:

  • More automation: AI increasing complexity of use cases - The range of use cases for automation will expand to address more complex business processes. In addition, the digital transformation momentum will continue to increase automation requirements and more organisations will create fully automated value chains. We’ll also see the emergence of more low code / no code platforms that address specific vertical needs.
  • AI will change the content creation paradigm - New algorithms and deep learning solutions are lowering the bar when it comes to creating highly-realistic content. For example, programmable avatars using a simple text editor. There’ll also be an increasing range of AI uses-cases, from AI-assisted video and picture editing through to synthetic video and voice, and 3D pictures for ecommerce. With algorithms progressing, AI will likely allow for even more real-time content creation, unlock marketing use-cases with deep levels of personalisation
  • Security focusing on cloud - As business applications and IT infrastructure will continue to shift to the cloud the need for cloud security will continue to increase and address misconfigurations and code vulnerabilities. The distributed workforce will continue to add impetus to the zero trust architecture imperative and infrastructure as code will lead to the convergence of code security, application security and cloud security.
  • API-ification of fintech infrastructure - Banking infrastructure tooling is now productised and also targets non-fintechs. Outsourcing compliance and API-first implementations shorten lead times. Access to non-banking data, such as payroll, insurance, credit and ERP, through APIs is enabling new use cases. 
  • The rapid rise of crypto and DeFi infrastructure - Institutional demand is rising and major banks and payments players are now incorporating crypto payments / custody. In addition, consumer demand is exploding as online exchanges, neobrokers and digital banks act as enablers and new use cases are emerging. For example, DeFi and NFTs. Continued development of Ethereum and other protocols is also resulting in increased scalability
  • Increased infrastructure for the anywhere workforce - As the world shifts to a hybrid workplace, mixing office and remote work, the need for new collaboration tools is set to increase. With the rise of remote working, companies will be pushed to look further afield to hire talent, which will result in challenging compliance issues. The need to make effective use of internal talent will be greater than ever and AI will unleash a new generation of talent marketplaces


********************



Sunday, September 12, 2021

“To build a community, you need to focus much more on the user than on the buyer” - Snyk’s Guy Podjarny

 


Cybersecurity unicorn Snyk was founded in 2015 with the mission to help developers make their code secure. Just a few years on and Snyk has evolved from being an open source vulnerabilities scanner and to becoming the world’s first developer security platform that start-ups worldwide can build upon. Snyk customers and users collectively have run more than 300 million tests in the last 12 months and fixed more than 30 million vulnerabilities in the last 90 days.

 

As the company announces its $530 million Series F at a valuation of $8.5 billion, it’s clear that Snyk is driving the industry’s shift to a new developer-centric approach to security and is now the undeniable leader in this space. In 2021 so far, the company has:

 

  • Increased annual recurring revenue by 154% year-over-year
  • Grown its customer base to 1,200+ companies, including established enterprise leaders and emerging hypergrowth technology companies
  • Hired and onboarded 320 employees, projecting 800+ by year end
  • Delivered more than 40+ new product features
  • Acquired FossID to expand license compliance and C/C++ capabilities


I sat down with co-founder Guy Podjarny to get his tips on building a community, how to deal with hypergrowth, the importance of having people across multiple offices and continents feel like one team and more…

 

Let’s start with your entrepreneurial journey. You’re a serial entrepreneur - some of your companies have been acquired and Snyk’s a great success. What attracted you to entrepreneurship, coming out of the 8200 Intelligence Unit?

 

I’ve always been interested in creation, in finding problems, and figuring out and creating solutions. That’s what I found most attractive about software development: building things. And I’ve always taken initiative. As an employee, I never waited for instructions to do something. So at some point I concluded it’d be an interesting adventure to try and actually found a company.

 

I was at IBM at the time. They’d acquired a company that had acquired a company I was at, and I didn’t want to stay there – it wasn’t the right environment for me. Founding my own company made sense. The idea, and how to tackle it, were secondary considerations. It was really all about building and creating solutions. 

 

Even within companies, I found myself constantly looking for the next mountain, and how I could learn something new. How could I grow my impact? That always brought me back to looking for bigger problems to solve. The specific idea would always come afterwards. 

 

What was your approach to picking co-founders, and what advice would you give entrepreneurs on this?

 

I think having a co-founder is very important. The entrepreneurship journey is hard. Founding companies is an emotional roller-coaster - you have highs and lows, sometimes several times a day, and they can get pretty extreme. You need close partners in that journey and you get many sorts of partners - investors, employees etc. - but you need someone who’s into the cause and all in with you. I’ve seen people succeed as solo founders – but I think not having a co-founder makes an already hard journey that much harder. For me, it was clear I needed a co-founder and that they could bring in a relevant skill set that I didn’t have.

 

Mike Weider, my co-founder at Blaze, was a much more experienced, technology-minded business person than me, and much better connected to the VC world. So, while he was CEO, leading the company and helping to fundraise, I focused on building the technology and product.

 

For Snyk, I was based in London, and wanted a branch in Tel Aviv, building a security company. I needed someone who was all in with me in Israel and wanted them to be the opposite of what I had with Mike at Blaze – I wanted someone who’d drive the technology while I could evolve as a CEO and build out the go-to-market strategy. A complementary relationship is important. You need to have enough overlap to communicate well and build the same thing together, but not so much that you’re both redundant.

 

It’s important, too, to have some background with your co-founder, or certainly a strong reason to believe you’ll enjoy spending a lot of time together. You’ll be persevering through some very hard times and it’s a long journey. The co-founder / marriage analogy is apt. If you fall out, the “divorce” can be very painful. I think not having any history together can be super risky.

 

You mentioned you first wanted to build a company and then try to find the idea. What was the lightbulb moment for Snyk?

 

The idea came to me in the shower! I’d been in security for over a decade, building application security solutions, but we weren’t successful in persuading developers to embrace them. In hindsight, I realise we built security solutions that we integrated into a development environment but we didn’t build the tools to be developer friendly. 

 

I left security and founded Blaze, a web performance company, where I spent seven years or so at the front line of the evolving DevOps movement. I learned to appreciate two things. The first was that DevOps changed the world of software. It really drives everything into these independent teams that will run, and security has to be a part of the movement, or we’re never going to be secure. The only way to scale security is to have security built into these development teams’ activities. The second thing was that DevOps gives us a playbook - it has taught us how to build great developer tools that are embraced by developers. That was my lightbulb moment - what if we build a DevOps tool that tackles security? 

 

I think ideas through by talking about them. The more I talked about this one, the more convinced I was that it was necessary. I wouldn’t let it go and it evolved into what we today call “dev first security”. The rest is history. 

 

Did you have to work hard to convince (co-founders) Assaf and Danny to join?

 

They were both about to found a different startup, so I didn’t need to convince them to found a company – I just needed to convince them to join mine! Fortunately, they weren’t too far along with their idea. It was still fairly abstract, while mine was very concrete and compelling – and, because of my past relationships with the investors, I already had funding lined up. I visited Israel and, after a bunch of meals together, they decided to join. It wasn’t easy, but it wasn’t the hardest part of the journey. 

 

When you started Snyk, did you think about the importance of building a community from the offset, and is that what drove your decisions in terms of building and architecting the product?

 

Everything you build in a company or solution should really revolve around the eventual users’ pains and needs – especially if you’re building from the bottom up. Snyk was a developer-first security company. The whole thesis was to build a developer tooling company that tackled security. Everything about it was built through that lens.

 

The go-to-market strategy was to start free and open source and grow from there. The community approach is instrumental to the developer tooling landscape. Developers look to the open-source community to see what’s being used there; they ask their peers; they like to try before they buy – to get their hands dirty. Everything was designed to mimic what I believe to be best-of-breed developer tools. 

 

The other model we had was DevOps, and we wanted to bring security back into the fold of DevOps. It’s a community movement, rather than a technology or specific practice. So it was important to mobilise the notion of developers needing to take on security and to help them embrace it. This drove a lot of educational activities within this conceptual community, which led to business impact from the bottom up, while the freemium self-service model helped us get people on the platform and start tackling that mission. 

 

What tips would you give to entrepreneurs who want to build a community – particularly a developer community?

 

First, you have to think about the user. If you’re talking about a bottom-up play, it needs to focus much more on the user than on the buyer. You need to ask how these users find out about and consume technology, and orient your presence toward this. In the case of developer tools, discovery and usage are often very community-based. 

 

You also need to think about whether you’re trying to get these communities to embrace a new practice. Sometimes you’re shipping products that are doing something that’s already been done, they’re just doing it better. So you might just need greater awareness and reach. But if, like Snyk, you’re trying to change behaviour and persuade a community to embrace a new practice, you may want to think about thought leadership, and maybe even investing in certain communities. 

 

Finally, if you’re building a platform, and you want to pull people in to create plugins and additions – especially if it’s open source – you should also think about appealing to a community of builders. This is similar but not identical to the community of users.

 

One thing that’s been particularly impressive is the speed at which Snyk expanded internationally. Starting in three cities - Tel Aviv, London and Boston - at almost the same time helped, but can you walk us through how you thought about building a global company from day one? What have you learned from it?

 

The company started as a two-headed monster, evolving into three and four heads with Ottawa and Boston. We ensured each office – with its own talent pools – was part of one team. We intentionally divided the teams so they never existed in one office alone – each was present in at least two offices. This required more effort but it also forced us to write things down and communicate asynchronously.  

 

Bringing together people, perspectives, skills and opinions from different locations prevents an “us versus them” mentality


that can arise when every office specialises in a particular topic. There’s a lot of family and cultural value in having local presences but as part of a global company, and it’s an approach that’s helped as we’ve continued our international expansion. “One team” is one of Snyk’s core values

 

Commercially, it’s all about reach. The technology problem, the people problem, and the user pain the company solves are international. Anyone embracing DevOps that cares about security should use Snyk’s solutions to help them build security into their software development practices. The whole go-to-market motion is product-led and has naturally expanded globally so it’s been international from the beginning. We let the technology community spread it wherever it may go and then complemented this with an inside sales team, supporting anybody coming in and wanting to upgrade. This team then grew, becoming more time-zone friendly, evolving internationally, but always with a local presence. 

 

Instead of pursuing big economies, we’ve followed the users, and grown in the Nordics, the UK, and Spain. In the complicated APAC market, we’ve had to combine the community adoption concept with an intentional presence, as well as an understanding of how business is conducted regionally and how to reach local communities. As at the beginning, we’re helping users in the region embrace the product by fulfilling inbound demand, and reaching out to similar users to ensure they’re aware of Snyk. 

 

Snyk went from low single digit revenue to $100 million+ in ARR in a record time, which is amazing. What did you learn in terms of hyper-growth and the shift from being a founder leading a small team to hundreds of people?

 

One of my key learnings is to

 

think further ahead than you originally believe – especially when hiring.


When you’re hiring leaders, you need people who’ll stretch to the full scope of responsibilities you’ll give them. In hyper-growth, that scope will multiply many-fold within a year or two. You don’t want to be in a position where, after your company has doubled or tripled in size and scope of activities, the person you’ve hired is suddenly in the biggest job they’ve ever done. It’s tempting to take a leap of faith with an external hire and think they’ll be able to stretch to the size, but it’s risky. You should only do this with internal hires who you feel can take the role on.

 

Secondly, don’t underestimate infrastructure. Putting something in place - like an internal system, for example - to suit the needs of your company today is risky. In a year’s time, when you’ve grown, that system will likely be too small for you and need replacing again. I’ve appreciated thinking a few steps ahead and investing in something that felt a bit too big at the time but suited our needs a year or so later. The future is closer than you think when it comes to both people and infrastructure!

 

And, finally, define clear boundaries. Once you’re successful, and opportunities are plentiful, your biggest enemy is a lack of focus. You must balance taking on new opportunities and not spreading yourself too thinly. By agreeing on certain boundaries for six or 12 months, it becomes harder to deviate from them. We drew a line while deliberating whether to do certain things or partner with certain companies. It made decisions easier, and helped everyone in the organisation maintain focus. 

 

After being CEO for the first four years, you hand-picked Peter McKay to take over in that role in 2019. Can you talk about that decision? 

 

Like picking co-founders, picking a CEO to lead the company at the right time is a crucial decision. Peter and I have known each other for eighteen years. When I was at Watchfire building AppScan, Peter was the President and CEO, and when I started Blaze and Snyk, I asked Peter to be on our Board of Directors. As I built Snyk over the years, it became clear that the market opportunity was enormous and that my role as founder was to ensure the longevity of our developer security vision, including our technology evolution and product roadmap. And, as we reached GTM maturity, it also became increasingly obvious that we were ready for an experienced operator like Peter to partner with me. Given that Peter was already on the Board, it was truly a no-brainer and then ultimately a seamless transition.

 

Looking back at when you closed your Series A in 2018, what do you wish you’d known then that you know now?

 

Many things! My earlier point about hiring is one. I think I’d equip the business better in terms of data. Back then I could just about hold the business in my head and understand what was moving. I had enough exposure to deals, product features and such that I could make good decisions and the exec team could make good decisions based largely on intuition. But as the business grew, this became dangerous as I’d have less detail on what was really going on. So I’d have invested in more data around the business and product, and become a more data-driven organisation at that time - it’s less painful to do this earlier on.

 

Snyk’s been very proactive throughout its lifecycle, raising rounds ahead of time. What advice would you give when it comes to choosing an investor, and the timing of financing?

 

Most importantly, an investor must be someone you get along with. You’re going to spend a lot of time with them. Just as with co-founders, you need to be happy about this, and feel like you’re having productive conversations. Even if they’re great at what they do, they may be the wrong fit for you personally. 

 

I’m a fan of stage-appropriate and stage-focused companies. Different funds and partners excel at different phases. I’m sure there are amazing individuals and companies that go all the way from seed to super-growth, but there’s a mental state and organisational setup for firms more attuned to just a couple of rounds. Be mindful of the stage you’re in.

 

You also want investors to have knowledge and experience in areas you appreciate. It could be a market, like DevOps in our case, or it could be a stage. Ask yourself - what do they know that I can tap into and benefit from? You want to have investors that can help you a lot and add a lot of value in a little time.

 

That makes a lot of sense. What’s been the hardest part of building Snyk that you didn’t anticipate, and what’s been easier than you expected? 

 

The hardest thing has been saying no to exciting opportunities in the name of focus.

You see many things on the road ahead, but you have to stagger them. I can’t do everything. If I try, it’s gonna fail!

 

The easiest was finding funding when things were going well. I think the market’s set up for investors to actively find companies that are succeeding. Capable investors found us more easily when we were doing well. I don’t think it’s a coincidence. The best investors have their ears to the ground and will find you.

 

And, in closing, are there any valuable life hacks or habits you’ve developed over the years to cope with the demands of founding a startup?

 

Whether it’s relaxing or spending time with the family, define your non-work boundaries so you don’t need to decide on them every time.

 

For me, I leave the office at 6:30pm and go home to have dinner with my kids and might be back at my computer at 9pm once they’re in bed. I also try not to travel on weekends and do back-to-back trips. It’s an approach that’s helped me stay sane and feel like I’m not constantly working.‍

 

***************************

 

Read our Secrets to Scaling interviews with:

 

- Personio's Hanno Renner here

 

- Chainalysis' Michael Gronager here

 

- BlaBlaCar's Nicolas Brusson here

 

- Supercell's Ilkka Paananen here

 

- Miro's Andrey Khusid here‍

 

- Trade Republic’s Christian Hecker here 



Friday, July 23, 2021

Accel 2021 Euroscape submissions are open - apply now!


- This article was co-authored with my colleagues Lucy Wimmer, Varun Purandare and Candice du Fretay. The Accel 2021 Euroscape will be presented at SaaStock in October.

You can now put your company forward for Accel’s 2021 Euroscape, the list of the top 100 SaaS companies across Europe and Israel. All information submitted is confidential and applications close on 31 August, 2021. If you want the chance to increase your company’s visibility across the ecosystem, APPLY NOW!

It’s now five years since Accel launched its inaugural Euroscape report - SaaS Wars: Europe Awakens. Back then, we could already see that SaaS was exploding in both quantity and quality of companies:

  • 50% of our 10 most recent investments in Europe were SaaS companies
  • The number of companies had grown 4x between 2007-09 and 2013-15
  • The amount raised by European SaaS companies had more than doubled 

However, the increased activity at the early stages had yet to translate into exits, with only four major exits as Qlik, Wix, Zendesk and Mimecast IPOed. The combined market cap of these companies was around $9 billion. By comparison, the US had seen around 60 SaaS IPOs with a combined market cap of close to $140 billion.

Five years on and Europe and Israel’s SaaS landscape hasn’t just awoken, it’s well and truly soaring at all stages. Last year saw an explosion of investment in private cloud companies founded in Europe and Israel, with funding hitting $13 billion. Not only is this a far cry from the less than $1 billion invested in 2016, it represented around 50% of the US market. The market cap of public cloud companies in Europe and Israel also hit $124 billion, which is just a slight jump from 2016’s $9bn ;)!

So, what’s in store for 2021? We’re only halfway through the year and Europe and Israel’s SaaS companies are already making history. Just over a year since it announced its seed round, Hopin announced its $400 million Series C at a $5.65 billion valuation to become the fastest growing company in history. Not long after this - and hot on the heels of its crowning as Europe’s first SaaS decacorn last summer - UiPath’s IPO in April saw it become the largest public cloud company born in Europe, with a market cap of over $40 billion. Then, this summer, Celonis secured the largest private SaaS investment globally ($1 billion Series D), securing the company’s spot as Germany and New York’s most valuable start-up at a valuation of $11 billion.

With the largest IPO, largest private funding round and fastest growing company from seed to $5 billion+, are we witnessing Europe and Israel taking the lead in the global SaaS race?

Across Europe and Israel, 2021 is already set to become a SaaS record-breaker. As of 23 April, 2020, investment in private European and Israeli cloud companies had already hit $8 billion and the region had created $153 billion public market cap. 

If you think your company has what it takes to feature in our 2021 Euroscape, APPLY NOW! Submissions close on 31 August, 2021. If your submission is successful, your company will feature in the Euroscape Top 100 list and associated content.

Similar to previous editions, the Euroscape ranking will be based on strategic and competitive positioning, growth rate and customer feedback via our partnership with G2.

We’ll unveil the 2021 Accel Euroscape on October 12-14 2021 at SaaStock. See you there (virtually)!


Thursday, June 24, 2021

“Growth and scaling are the hardest things to get right” - Chainalysis’ Michael Gronager


Earlier this year, Chainalysis announced its $100 million funding round, valuing the company at more than $2 billion and marking the fact that cryptocurrency is now mainstream. Since its Series C in November 2020, Chainalysis has increased ARR by more than 100% year-over-year, doubled its client base and now supports more than 100 digital assets across 10 native blockchains (around 90% of cryptocurrency economic activity). It’s been quite a journey getting here and there’s still a way to go as cryptocurrencies integrate with our global financial system.

I sat down (virtually) with Chainalysis co-founder and CEO Michael Gronager to discuss his learnings from almost seven years at the helm of a high-growth company. He shared his tips for building a global business, hiring, what he’d do differently and more…


The Chainalysis journey

PB: Let’s go back to the start. What was your career prior to founding first Kraken and then Chainalysis? What attracted you to entrepreneurship?

Before Kraken, I was planning and running public research infrastructure projects across Europe. Essentially, I was just doing politics and talking to research councils to get funding. I got to a point where I thought the purpose of the education and research systems we were creating was for people to build companies and that those who could do, should. After a conversation with a colleague, I decided to build something myself. I started coding iPhone apps and got one off the ground for a US company. This gave me some financial freedom, so I quit my job and was soon bitten by the crypto bug. 

I started reading about Bitcoin when the price went crazy high - growing from $1 to $32! - and then crashed to $15 in 2011. I saw Bitcoin as a new paradigm in computing, creating digital scarcity where something digital couldn't be copied and you could only transfer its value or symbolic value. I looked for places to meet other people who thought Bitcoin was cool and found the first ever conference in New York. I met [Kraken co-founder] Jesse Powell here.

How did Kraken come about?

I’d been experimenting with distributed payments online and couldn't figure out whether to create a business around this or not when Jesse contacted me about a crypto exchange he was building. It sounded fun, so I went to San Francisco to join the team and Kraken launched in summer 2013. It was perfect timing - Bitcoin that year went from $10 to $1,000.

How did you get from there to Chainalysis?

Mt Gox, the biggest crypto exchange, went bankrupt in early 2014, losing about half a billion dollars following a hack. This caused a big downward spiral of everything crypto. It was associated with criminal activity, hacks, online drug sales, terrorism and more. No one wanted to talk about crypto, so running an exchange was tough. Talking to banks and regulators in Asia, Europe and the US, I kept hearing the same issues: they couldn't monitor transactions, no one understood the return of funds, and - most concerning - crime couldn’t be investigated. I thought about this, read the original Satoshi article and others on how it was possible to trace, execute and build a data layer crypto. I then decided to try and solve the obvious problem of understanding the flow of funds in the most transparent financial ecosystem ever created.

I left Kraken and created the Chainalysis prototype on my flight back to Europe. I had a lot of Bitcoin code and software so the proof of concept was basically 50 lines of code. I could build out clusters of transactions, enabling you to see different services and create the early map of crypto. It was then a case of finalising it, bringing Jonathan and Jan on board, selling it, and here we are!

Learnings for the next generation of entrepreneurs

Many European founders wonder where to start their company - move to the US or stay in Europe. Why did you decide on New York and then build Chainalysis’ organisation between there and Copenhagen? 

In the best of all worlds, we’d have probably moved to San Francisco. There’s great talent, a lot of investment and programmes like Y Combinator. You can get capital and be up and running in the blink of an eye. But, when setting up, we wanted to maintain a European connection for developer resourcing and build some of the team out there. I also had family in Europe. Having a nine hour time difference between Copenhagen and San Francisco didn’t make sense. Proximity to Washington DC was going to be key for US government customers and the heart of finance was in New York so it made sense to set up shop there. There are two key reasons we didn’t just stay in Europe: there’s a sales momentum and energy in the US that we wanted to tap into to win the global market, and building trust with US government agencies would have been harder if we were seen as a European company. We had to be US-based.

How did you initially think about going global from a sales perspective? With the crypto ecosystem, you’ve got a big buyer in US government agencies, Chainalysis’ European roots, the UK’s GCHQ, and a lot of crypto activity in Asia. It's challenging for a young company to deal with three continents and time zones for sales. How did you do it?

We ran a lot of our sales calls over Skype, sitting in various places doing early or late calls every day with exchanges or law enforcement agencies worldwide. It worked pretty well. We were quite successful selling the product to both government agencies and exchanges purely online. But growing these accounts later typically required travel. Once the customer had bought the product, we had to get on a plane to drive adoption and upsells. I’d be jumping all over the world for these meetings. It was a lot of travel. One of the things I’ve enjoyed with the pandemic is not always sitting on a plane!

Now you’ve had five or six years of global expansion, is there anything you’d do differently?

I think that setting up and building a team in one office with a strong focus on product and design and so on would have been a slight advantage over hiring people via the internet all over the world, so I’d probably do that now.

I’d maybe even have moved to the West Coast at the beginning. When you’re trying to attract commercial talent at higher levels, it still has an advantage. It’s probably 10 times the talent pool of the East Coast and another 10 times that of Europe. This isn’t the case when hiring engineers - the quality across Europe is better than most of the US, in my opinion. But for leaders in sales and marketing, there’s a lot of high growth company history on the West Coast to draw talent from. 

Let’s dig into this. Hiring execs is one of the most important things for high growth companies. How do you view the composition of your team and proportion of people who’ve done the job before versus those growing into roles?

I think it was Eric Vishria who said he’d split it so 75% of the team have done the job before and 25% are growing into roles. I think that's right, but the key question is: “what does it mean to have done the job before?”. There are probably only a couple of COOs who’ve successfully built a company from $5m to $5bn revenue over 10 years and they likely don’t need or want to work anymore. I’m looking for people who’ve experienced high growth. There are tons of companies that have built hundreds of millions of revenue over 20 to 30 years, companies growing at 20-30% year-over-year. These companies grow at a pace most people can handle. They don't experience the same issues as high growth companies and it’s the high growth experience I’m interested in.

It’s important to me that they've been part of the ride overall and seen a company fall apart constantly and need fixing. You're basically driving a car too fast. But high speed racing cars are meant to fall apart. They regularly need new engines and tires and that’s what happens to a company when it grows at 80-100% year-over-year: you need to have the mindset that Band-Aids are your best friend and the company needs duct tape all over. Getting the company into this mode of constantly fixing and changing every component is the hard part. I'm looking for two thirds to three quarters of the team to have experienced that.

I like the racing car analogy - it brings me nicely to the role of company culture and values in keeping things together. What values have you created for Chainalysis?

Early on, we got a lot of cultural input from Techstars. We inherited their value “Give first”, a way of interacting with others so everyone wins. The other value to highlight is “radical gradualism”, which means aiming big but understanding there are many subtle, smaller steps that need to be applied along the way. This is very relevant to the early crypto days where everyone would say, “we’re taking over the world this year, governments are gone, everything’s done and this is happening now”. But this isn’t how change happens. Even the internet took 20 years and that’s fast for global change. Understanding all the steps and winning over stakeholders in the right order is the important part. Radical gradualism can be applied to problem-solving all over the company. Have the mindset of getting to the moon, but recognise there are many steps to building the rocket and getting it into orbit and beyond.

Chainalysis has developed a very mission-driven attitude from working closely with law enforcement. Many things we’re doing are seriously important - people's lives are at stake - and they’ve become a core part of our company culture. More important than value creation, it’s the bigger goal of creating a better world.

This is an important point. Chainalysis has been involved in some high profile cases. What accomplishments are you most proud of?

One that stands out for me is our involvement in the shutdown of the largest ever child pornography site in October 2019. There were more than 300 arrests across 38 countries and at least 23 minors were identified and rescued from abusers as a result of this investigation. I felt that if this was the only thing I ever accomplished it would be good enough for me.

Last year also saw the largest seizure of cryptocurrency - more than $1 billion - in the Department of Justice’s history. We’ve got a lot of “biggest, fastest, most important” cases on our resume and they're all cases to be proud of.

Looking back to when you started Chainalysis, what do you wish you’d known then that you can share with the next generation of founders?

I wish I’d properly understood the nature of fast growth and getting it right from the beginning. Growth and scaling are the hardest things to get right. We all get excited when we see growth for the first time. But it’s important to understand that getting to the point where you have a product, some customers and a million or two in revenue is just the start. Many companies get there, but never figure out how to scale beyond this. Maybe there’s no product-market fit, for example. Or maybe they do scale, but headaches start because they do it too quickly. It’s tempting to grow fast, but it’s hard to reach a stable growth curve. Growing by more than 100% is tough - it’s a muscle that needs to be built over time.

Building a business is always tough especially when growing as fast as Chainalysis. Are there any tips or life hacks you’d share with other entrepreneurs?

Developing routines helps in various ways. I try to exercise every morning, getting up and running so I know it’s done ahead of a day packed with meetings. I try to find joy in the small things. Ensure you have some of that during the day - whether it’s your morning run or cooking, for example. I like to cook as you can mentally get into another zone.

Try to also take one day off a week. I can’t take two days off, but I try to have Saturday as a reset day. Get your mind in another place and don’t think about work for several hours. It’s important for mental health as the other days will be 100% occupied with work.

What’s been the hardest thing about building Chainalysis that you didn’t anticipate?

Probably the fact you become another person on this journey. And you want to, but there's stuff you sacrifice. Not spending much time with my kids is tough. But when you're building something and you get into this mindset, it’s like you’ve swallowed a pill. Change just happens. Some of the life changes are tough, but you get to experience things that very few people do. I'm deeply grateful for that and hope I can share some of this with my kids at some point - this is a journey I can bring them on in various ways too.