Not Every Groundbreaking Idea Needs to Become a Startup
Ross Haleliuk
BSidesSF 2025 — Here Be Dragons · Day 2 · Main
Overview
The cybersecurity industry has convinced itself that venture-backed startups are the only path to solving security problems — and that assumption is quietly strangling hundreds of niche but important problems that will never fit the venture scale model. Ross Haleliuk, author, angel investor, and product leader, argues for a broader menu: bootstrapping, the "Silicon Valley small business" model, services companies, open source, conference talks, and standards bodies all have roles to play. ---

Key moments
- 1:59 Thesis: 4,000+ security vendors yet most problems go unsolved
- 4:00 Key insight: venture scale requires returns of 20-50x capital in 5-10 years
- 5:59 Core argument: most security startups tackle sub-venture-scale problems
- 6:59 VC model is harmful when it mandates growth the market can't support
- 8:29 Sub-venture-scale examples: EDR-MDM gap, HRIS identity sync, Slack alert triage
- 10:00 Niche problems are opportunities: founders can profit without VC pressure
- 11:00 Alternative model #1: traditional VC path — benefits vs. drawbacks explained
- 12:00 Pivotal question: what non-VC models exist for security founders?
Not Every Groundbreaking Idea Needs to Become a Startup
Speakers: Ross Haleliuk
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch on YouTube
Reading time: ~8 minutes
TL;DR
The cybersecurity industry has convinced itself that venture-backed startups are the only path to solving security problems — and that assumption is quietly strangling hundreds of niche but important problems that will never fit the venture scale model. Ross Haleliuk, author, angel investor, and product leader, argues for a broader menu: bootstrapping, the "Silicon Valley small business" model, services companies, open source, conference talks, and standards bodies all have roles to play.
Introduction
Ross Haleliuk opened with a slide that most BSidesSF attendees had probably seen before: the famous security vendor landscape, listing thousands of companies organized by category. His observation was pointed — that diagram only shows the biggest and highest-traction players. There are roughly 4,000 more. And yet, for all that coverage, the industry keeps producing startups that address problems that don't exist while genuinely important niche problems go unsolved.
Haleliuk speaks with authority on the business side of security. Born in Ukraine, now based in San Francisco after stints in Canada, he has worked across fintech, wholesale retail, and cybersecurity, with a career focused on product management and go-to-market. He advises security companies, has invested in them as an angel, wrote a book on building cybersecurity startups, and is currently building one himself. His thesis for this talk: the venture capital model dominates the conversation about how to build security companies, but it is the wrong tool for a large fraction of the problems that need solving.
Why Venture Scale Dominates — and Why That's a Problem
▶ Watch: Venture scale economics and market dynamics (05:00)
The gravitational pull of VC funding in cybersecurity is real and, Haleliuk argued, for understandable reasons. Security buyers are predominantly enterprises, which means security startups face enterprise sales from day one — long procurement cycles (12–18 months is common), demanding technical requirements, and the expectation of production-grade reliability before the product is proven. Companies like Okta, CrowdStrike, and Palo Alto Networks all started by selling to enterprises. That requires capital: to hire experienced people, fund R&D, and survive the sales cycle without revenue.
The numbers around large acquisitions reinforce the narrative. Cisco's transformation from a networking company to a security powerhouse — through acquisitions of Splunk, Duo Security, OpenDNS, and SourceFire — and Google's purchase of Mandiant (the largest acquisition in the company's history) make security deals regular headlines in the tech press. Investors are excited. Venture scale looks like the obvious template.
But here is the problem: venture scale requires three things simultaneously — a large addressable market, a large number of people experiencing the problem, and those people having deep pockets and willingness to pay. Most security problems satisfy none of these criteria. Security threat profiles are specific to industry verticals: a manufacturer's concerns differ fundamentally from a SaaS vendor's, which differ from a cloud provider's. Target markets for many security solutions are genuinely niche. The venture model requires the problem to be big; most security problems aren't.
This mismatch has a compounding effect. If venture is treated as the only path, the logical implication is that problems too small for venture scale will simply never get solved. Haleliuk cited research by Kane Narraway and Ramy — who happened to be in the audience — that describes "sub-venture scale security problems": endpoint vulnerability automation (connecting EDR vulnerability data to MDM patching without an easy off-the-shelf solution), downstream HRIS identity problems (human resource system changes creating security team headaches), and alert triage via Slack integrations. All real, all important, all currently requiring significant custom effort to solve. None are obviously venture scale.
Four Models for Building Security Companies
▶ Watch: Alternative funding and company models (12:00)
Haleliuk walked through four models, each with its own risk profile and appropriate use case:
Model 1: Traditional VC path. The default. Capital for growth, networks for hiring, market access, and the Techcrunch-article credibility that generates LinkedIn posts and recruitment appeal. The drawbacks are equally well-known: high pressure for unsustainable growth, forced expansion faster than product readiness, dilution, loss of founder control, and exit pressure that can run companies into the ground trying to satisfy return expectations. Appropriate when the market opportunity is genuinely massive, first-mover advantage is critical, and significant GTM investment is needed from day one.
Model 2: Bootstrapping. Haleliuk calls it "the hard way" — and means it as a compliment. Profitable from day one, lean operations, efficient capital. Often starts with services and builds toward a product. Think Canary: more than 2,000 paying customers, nearly $20 million ARR, profitable from year one, deployed on all seven continents, never took VC money. Or Enzime, a newer entrant in network security. The upside is complete founder control, no exit pressure, and the ability to build a genuinely profitable niche business. The downside is slower growth, the need for early revenue (which pushes companies toward services), and the difficulty of attracting talent without the Techcrunch halo. Best suited when venture scale isn't necessary, the founders have strong existing industry networks, and the market doesn't require massive day-one investment.
Model 3: Silicon Valley Small Business (SVSB). A newer concept — raise one round, become profitable, and never raise again. Haleliuk acknowledged that this path is rarely explicitly adopted by companies, but that there are plenty of security companies that raised one or two early rounds and then grew into successful businesses without subsequent raises. The challenge is that most VCs investing in that first round expect the standard growth-and-exit trajectory. Getting alignment upfront that the company will not pursue follow-on funding is difficult. Best suited when the market values efficiency over hypergrowth, the team can operate profitably at small scale, and AI or automation lets a small team punch above its weight.
Model 4: Services. The most overlooked model, given the noise around product companies. Services constitute over 50% of the cybersecurity industry. Most M&A in security happens in the services space — another fact easy to lose sight of given how product company acquisitions dominate headlines. Services companies can start generating revenue quickly, start lean, and avoid early VC dependence. The drawbacks are lower margins than SaaS, linear scaling (more business requires more people), and difficulty differentiating.
The AI opportunity here is real: VCs are actively beginning to fund "AI-enabled services" companies for the first time, based on the thesis that AI can break the traditional link between revenue growth and headcount growth. Whether AI actually changes the economics of services delivery at scale remains an open question — some companies have achieved 95–97% automation of service delivery and still have not dominated their markets — but this may be the best window in history to raise VC money for a services company.
Beyond Business: Other Ways to Solve Security Problems
▶ Watch: Non-commercial paths — open source, standards, talks (23:00)
The final section of the talk challenged the assumption that every good security idea needs to be monetized at all. Haleliuk outlined several non-commercial vehicles:
Nonprofits for mission-driven work that is genuinely public-good focused and not profit-driven. Conference talks — a path Haleliuk specifically recommended for early-stage ideas seeking feedback, or for topics that are valuable but not substantial enough for a standalone business. Standards bodies for technology that would benefit from broader adoption through community involvement rather than commercial control. Open source for software that benefits from community contributions — Haleliuk cited SPIFFE/SPIRE as an example. And simply writing and sharing research for ideas that are informative but not immediately actionable as products.
The Signal Foundation's trajectory is one of his examples: the founders gave talks, shared research, built community credibility, and then built a product that became one of the most trusted communication tools in the world. Snort went from open source IDS to a $2.7 billion company. Neither path started with a Series A pitch deck.
The framework Haleliuk offered for deciding between options: examine your motivations (money? passion? impact? lifestyle?), think through first-order consequences for each path, and remember that 10% of $100 million is the same as 100% of $10 million. That arithmetic reshapes many conversations about dilution and exit — particularly for founders in the services space who exit businesses they have built entirely with their own capital.
Notable Quotes
"Most security startups are tackling problems that are too small for the venture scale outcomes." — Ross Haleliuk (08:00)
"If we accept that the VC path is the only way to build security companies, we also have to accept that a large number of problems practitioners experience will never be solved." — Ross Haleliuk (10:00)
"Remember that 10% of $100 million is actually the same as 100% of $10 million." — Ross Haleliuk (25:00)
Key Takeaways
- Venture scale is a poor fit for most security problems. Security threat models are vertically specific and target markets are niche; most solutions will never reach the market size VCs require to make their return model work.
- Treating VC as the only path guarantees that sub-venture scale problems go unsolved. Endpoint vulnerability automation, HRIS identity integration, and alert triage via Slack are real problems that require solutions — but none will attract a Series A, so they will stay broken unless founders pursue alternative models.
- Bootstrapping produces durable, profitable businesses. Canary's profile — 2,000+ customers, nearly $20M ARR, profitable from year one, no external funding — is achievable in security for founders with strong practitioner networks and a willingness to start with services.
- AI is opening VC to services companies for the first time. If you have considered starting a services company in security, this may be the optimal window to do it with VC backing — but the thesis depends on AI genuinely changing service delivery economics, which remains unproven at scale.
- Not everything needs to be a business. Conference talks, open source projects, standards participation, and research publishing are all legitimate vehicles for delivering security value — and some of history's most impactful security tools started there before becoming companies.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Haleliuk is right that the security industry has an unhealthy fixation on VC as the only viable company-building model, and the sub-venture-scale problem category is a real and underserved gap. But this is a conference talk, not a research paper, and it mostly systematizes common knowledge for an audience that could use the reminder. Not groundbreaking, but not wrong.
Heather Calloway (CISO) — SOLID
Haleliuk makes a well-structured argument that venture capital is the wrong funding model for most security problems, and that treating it as the only model means genuinely important niche problems will stay broken. The Canary bootstrapping example is one of the few in security discourse that puts actual numbers on an alternative path.