Latest Blogs

from the Emerging Business Team

Core Infrastructure by Yi-Jian Ngo

Can Security Startups Succeed?

These days, you hear a lot more about “consolidation” and “maturity” in the security industry than about innovation. VC investments in security startups have halved over the last 2 years. And a recent survey by Goldman Sachs indicates that the growth of IT security budgets will decline from the double-digits to just 8% in 2008 and 6.5% in 2009


So it would seem that doing a security startup today is somewhat akin to train surfing. I beg to differ.


First, the fundamental drivers of security threats are accelerating.  Gary McGraw’s “Trinity of Trouble” describes these as connectivity (growth of the internet & web services), extensibility (widespread use of plug-ins, mashups) and complexity (exponential increase in the length of code bases).


It is unsustainable for the severity of threats to increase at a rate greater than the resources available to mitigate them – that trajectory implies that swathes of IT infrastructure will gradually be rendered unusable. I believe there is the opportunity for innovators to plug the gap with a different approach, possibly spawning the VCs’ holy grail – the next $1B+ security category. While only time would tell the details of its composition, I expect that aspects of automation and semantics will be involved.


Second, security is a perpetual game of cat-and-mouse, implying a continuous need to build new defenses to adapt to the shifting threat environment. So while things like anti-malware and anti-spam are indeed “mature”, the tectonics of technological innovation are exposing new surface areas of attack, from virtualization to rich internet applications to mobile phones.


While many enterprises tend to be more concerned about mature attack vectors than emerging ones, it usually takes just one CNN Moment for corporate wallets to rapidly spring open. And at that point, startups that have developed rock-solid defenses for those new attacks will find themselves well placed.


Filed under: ,
Published Tuesday, April 15, 2008 4:47 PM by Yi-Jian Ngo

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

No Comments

Leave a Comment

(required) 
(optional)
(required) 
Submit

About Yi-Jian Ngo

I have a passion for technology and want to apply that towards discovering and developing ideas into successful companies. At AT&T Strategic Ventures, my investments included OpenClovis, a telecom middleware vendor. I have executed $15B worth of M&A transactions, as well as held multiple operating roles in network engineering and global business development. Currently, I cover the enterprise infrastructure space for the Emerging Business Team, and focus on our strategic initiatives in China. I received my MBA from Cornell, and also hold degrees in Electronics Engineering and Law.
Yi-Jian Ngo
Core Infrastructure, Security and Storage
I have a passion for technology and want to apply that towards discovering and developing ideas into successful companies. At AT&T Strategic Ventures, my investments included OpenClovis, a telecom middleware vendor. I have executed $15B worth of M&A transactions, as well as held multiple operating roles in network en...

Recent Posts

Syndication

  • Subscribe in NewsGator Online
  • Add to Technorati Favorites