But you'd much rather have a small cold that lasts for a few days than have a very very bad flu that lasts for weeks or months. That narrative in the real world is the same in the cyber world. If 10 years ago a CISO walked in to his or her boss or board and said, "I guarantee you we're going to be breached one day in the future. You'd be fired for saying that. Now, flip the script a decade later. If a CISO were to ever walk in and say, "I guarantee you, we'll never be breached, I think they'd probably get fired for that. If the company were to go broke unexpectedly, hard to imagine, but if it were to happen, I believe that the responsibility for that ultimately solely rests with the CEO. I had a lot of conviction around the problem. I'd say absolute conviction. I had a lot of conviction that the incumbents were going to miss the ball, and those two things together, I think, gave me the conviction and the desire and the passion to say, let's go build a company to see if we can go win this.
Speaker 2 01:06
Cybersecurity used to be about prevention and keeping attackers out, but today many leaders are facing a different reality. Breaches are no longer rare events. The real question now isn't if an organization will be breached; it's how prepared they are when it happens. I'm Lara Nacesian, and this is CEO behind the scenes. Today, we're exploring what it means to operate in what many experts now call a post breach world, where resilience, visibility, and speed of response have become just as important as prevention. My guest is Andrew Rubin, founder and CEO of Illumio, a cybersecurity company recognized as a leader in microsegmentation and breach containment. Andrew has spent more than a decade challenging the way organizations think about security, helping build an entirely new category focused on stopping attacks from spreading once they're inside the network. Please enjoy, Andrew. Welcome to the show.
Speaker 1 02:18
Thank you so much for having me. It's great to be here.
S S S
Speaker 2 02:20
It's such a pleasure to have you, and I really want to start with the big picture because you've spoken about this concept that we're now living in a post breach world. What does that look like for organizations today?
Speaker 1 02:37
So the easiest way to frame it is just to think about not what we need to do going forward, but how we got here. For 50 years, give or take, cybersecurity's had one job, one mission, one responsibility, you could say, which is to keep bad things out, prevent breaches, stop things from happening before they actually happen. And unfortunately, the data and our track record show that although we're good at that, we're nowhere near perfect at that. We have breaches. Ransomware does hit organizations regularly all over the world, and so I would start by making the argument that it's not about throwing away everything we've done in the past, but it's about recognizing and maybe the right word is admitting that going forward, what we've done in the past alone is necessary, but it's no longer sufficient. That we do have to live with breaches. That these things happen, and they happen all the time. And when they do, they're damaging and they're expensive. So cyber gets a second job. It's not a replacement of the first job. We should prevent everything we possibly can, but it gets a second job, which is a focus on resilience and recovery, and making sure that when we have a problem, we focus as much on keeping it small as we do on preventing it from happening in the first place. And as funny as it sounds, it actually starts not with a technology conversation. It starts with a mindset. If you don't acknowledge you have the problem, you can't talk about what to do differently to fix it. We have a problem. The problem is breaches happen. We live in a world where there are now regular occurrences. We need to start thinking that way.
Speaker 2 04:20
And when you're speaking with executives and leaders that are outside of the the industry, outside of the cybersecurity world, whether they're CEOs, boards, business leaders, how do you explain that shift in mindset?
S S S
Speaker 1 04:35
Well, it's funny you ask now because if we were having this conversation a few months ago, I would have said with a lot of education, sometimes having to evangelize why they should think about it or care about it, and then there's this word that entered the public ecosystem called mythos, and I can assure you that although I don't want to turn the whole conversation into a conversation only about one model from. One frontier model company, it was the first, and it has changed just about everything, because all of a sudden everybody-and I don't mean just security or cybersecurity professionals-everybody, board members, CEOs, regulators-you can't obviously wake up in the morning or go to bed at night and not hear about Mythos and ChatGPT 56 and the Chinese equivalent of these models and the open source equivalent of these models to come. This is the first time where it's gone totally mainstream, and so this notion of resilience and recovery and maybe said a little more bluntly, how are we going to survive in a model cyber world? It has changed the conversation very dramatically.
Speaker 2 05:48
And one of the messages that that you touched on is that breaches are inevitable, but disasters may not be. You spoke about this concept of containment. So, what does that distinction look like in practice?
S S
Speaker 1 06:04
So it's super interesting because, at least for me, when I think about cybersecurity, and I mean the topic in general, and then all the way down to the technical details specifically, I think there are parallels to everything we do in cyber in sort of the real world. People talk about the cybersecurity world, I think there were parallels to what happens when we fight in the kinetic world, and I think there were parallels in sort of lots of other places in our lives. So I'm going to give you one that, for me, has always resonated, and maybe it's why the Illumio story and the segmentation story resonates. If I were to ask you how you think about your health. You would immediately understand, without anybody having to teach you anything or talk you through it, that when it comes to your health, you know it's not going to be perfect every single day of your life, but you'd much rather have a small cold that lasts for a few days, then have a very very bad flu that lasts for weeks or months. You know it. It's like we're all just sort of born with the knowledge that small problems are better than big problems when it comes to our health. But for some reason in cybersecurity, we've all managed to sort of ignore the lessons from the real world. We talk about a breach as if if one laptop has a problem, that's the same as 100,000 laptops having a problem, and it's not. One having a problem is a lot better than 100,000 having a problem, but we have had this narrative for so many decades, for so many years, that you're either perfectly healthy in cyber, or you're very very sick, and I think what we've all now started to realize very quickly is no. It turns out that that narrative in the real world is the same in the cyber world. If we focus on staying as healthy as possible as much of the time as we can, but occasionally we're going to get sick. Something will get infected, and immediately once that happens, we should shift all of our effort to trying to make sure that it stays as small a problem as possible. Now, in our world, there is a word for that. It's segmentation. That's the actual security control that was designed from the very beginning to contain things once they get in and try and spread. But I do find that it's funny that the concept that we we so naturally understand in so many other parts of the world we sort of have ignored in cyber for so long, which is containing things and keeping them small is a great outcome. It may not be as good as perfect, but it's the next best thing.
Speaker 2 08:48
I love that analogy around containing an illness and maintaining, you know, optimal health at most times. I think that's such a great visual depiction. From your perspective, why do you feel like there's such a challenge in the change in mindset and openness to looking at cybersecurity in the way that you've you've described it?
S S
Speaker 1 09:13
So I think there's a few things. It's a super important question because I really do believe that the only way you fix a problem, I don't care where that problem is or what it's about. You have to start by acknowledging that you have the problem, otherwise, you're never going to be willing to dedicate any resources or effort to fixing it. So I think the the question itself is super important, and I think there's a few things. Number one, let's take the person who ultimately is responsible for cybersecurity in any organization, the CISO, right? Obviously, it's a team sport in every company and every organization. But the person ultimately responsible at the top of that team is the CISO, the Chief Information Security Officer, or the Chief Security Officer. If 10 years ago a CISO walked. To his or her boss or board, and said, "I guarantee you, we're going to be breached one day in the future. You'd be fired for saying that. Now, flip the script a decade later. If a CISO were to ever walk in and say, "I guarantee you we'll never be breached, I think they'd probably get fired for that, we we had to get to a place where everybody was just comfortable acknowledging that these things happen, and it took a long time to get to a place where people were just okay acknowledging it. I think most of what got us there is that it just keeps happening again and again and again. But we got to a place where you couldn't deny it anymore. So there was that mindset shift that it's okay to talk about it out loud. That's one. I think the second thing is that we did grade ourselves on perfection. You were either breached or you were not, and we sort of very quickly learned the hard lesson that no, unfortunately, we're going to have to have a scale to grade a breach. That some of them are going to be small incidents, and some of them are going to be catastrophes. And if that's the case, we better start focusing on how to avoid the catastrophes. And so that became part of the conversation. And for me, the the third, and I would argue the most important one is that we all, as a community, meaning the industry and the customers that we work so hard to protect, we all got to this place where the industry didn't feel the obligation to promise perfect outcomes anymore. I don't want to blame the industry for putting us in that place in the first place, because I think it's a collective conversation. But the industry also has to be willing to acknowledge that you can buy our products, and we're going to help to protect you and keep you safe. But we're not putting a stamp or a guarantee on top of the box saying if you buy this, you will never have a problem again. And so none of these things were light switch events where they all happened or they happened at one moment in time, but I think over the last decade or so, we've seen a huge shift in just the entire conversation around cyber. And obviously, I believe it's the right one, and I think it's very healthy.
Speaker 2 12:17
And many companies continue to invest heavily in security tools, but as you've touched on, breaches keep happening. Where do you feel like the system is is failing?
S S
Speaker 1 12:30
I actually I'm fine with the word failing. By the way, I will say my my version of that word is I think that cybersecurity is broken. I've said it very openly, publicly, privately, and everywhere in between, and what I mean by that is this: If you actually look at the data, not how we feel, not how hard we try, whether it's the industry, the customers, the collective community, if you look at the data, here's what the data says: Every year, let's take the last 10 years. You could probably go further back, and it would tell the same story. But let's just say for the last decade, here's what the data tells us: Every year, venture capitalists invest more money into cybersecurity innovation. Every year, more cyber companies exist than the year before, startups and otherwise. Every year, more tools exist from the growing number of companies. Every year, customers spend more money on cybersecurity. It goes up at different rates year over year, but the line does not ever seem to go down. By the way, if you talk to those customers, they're going to tell you that every year they feel like they've got more tools and more products from more vendors. Everything is going up and to the right every year. The only thing that's going up and to the right faster is the number of breaches and the cost of those breaches, so anybody who's data driven would look at that and say, "You're telling me that we spend more, we buy more, we invest more every year, and the outcomes get worse every year. That doesn't feel like a winning mathematical formula, and so if you look at the data and it tells that story. You have to ask the question: Does that mean that everything we're doing is wrong? And that would be a silly conclusion. What it means is that we're over investing in certain things that aren't helping enough, and we're under investing in things that we probably need to invest in today. The world's changed. Cyber's changed. The threat landscape has changed. If we just keep buying more of the same, we're probably going to get outcomes that don't work any longer. And I think the data tells that story.
Speaker 2 14:54
From your perspective, what are some of those common blind spots or some of the. Areas that organizations may be overlooking.
S S
Speaker 1 15:04
So there's a famous expression in both, I'll call it kinetic or real-world security, as well as cybersecurity, and the expression holds perfectly in both. You can't possibly protect what you can't see. It's obvious. If you want to protect something, I don't care if it's the Secret Service protecting a protectee or it's somebody trying to protect their network infrastructure. If you want to protect something, the first step is to be able to see it and understand it in real time. Well, in the cyber world, so much of what we try to protect, we have no visibility into, or we sample our visibility and we look at it once a week or once a month or once a quarter, and we check a box and pretend that that's good enough. But in the world we live in today, the attackers are 24 by 7. Obviously, all of that is only going to ratchet up exponentially when we start throwing AI and machine speed at all this, and so we have huge. You ask the question blind spots in a literal sense. We have huge blind spots. We don't understand how things talk to each other across our networks. We don't understand when things start communicating that shouldn't be, we don't understand when our data is getting sent out somewhere and it should never be leaving, let alone going to this place that makes no sense. Usually, the way we find out about all these problems is because something catastrophic happens, and then we look back and say, "Oh my gosh, I can't believe for the last six months somebody has been doing this to me, but the question we should be asking is why didn't we know five months and 29 days ago that this started happening and start scratching our head and asking this doesn't seem normal. We should go dig into this, and the reason is because we've been flying fairly blind in many parts of our IT estate for a very long time. I think one of the first things we need to do is dramatically increase the observability and visibility of our environment. And I do believe with what's coming with AI and machine speed and empowering attackers to move much faster. If we don't do it, we're going to be at an even bigger disadvantage than we already are.
Speaker 2 17:25
And let's talk about that because, from your expertise and from what you've seen, what is it that allows attackers, once they've entered into a network, to be able to create such widespread damage and at the speed that they do.
S S
Speaker 1 17:43
So what's ironic is they don't actually do it all that quickly. So there's a term in cybersecurity. It's been around for a very very long time called dwell time. And again, kind of like the health example that we used a few minutes ago. I think there's a very real parallel in the real world, so I'll define dwell time in cyber terms, but then the parallel I think really puts sort of that easy picture in your head. Dwell time is how long an attacker is able to get in and live inside of somebody's environment undiscovered. That's why they call it dwell time because they're dwelling inside of the environment, inside of the network, but they're undiscovered. They're there, and nobody knows they're there. So here's the real world equivalent: when you go home after work today to your flat or your house, and you walk in your front door, let's pretend that I was there, and we know each other because we're having this conversation. But I'm certain that you have not invited me over to your flat or your home. And let's pretend that I was there when you got home today, but you didn't know I was there, and I wasn't just there sitting on the couch where I said, "Hey, it's great to see you. I was there. I went in the bedroom. I went in the kitchen and cooked myself a meal, and then tomorrow morning you get up and you have your coffee or your flat white, and then you head to work, and I'm still there. And this goes on for the next nine months. Nine months, not nine hours, not nine days, but for nine months, and I'm literally living in your home, and you don't know I'm there. Well, take a guess what the average dwell time for breaches has been pretty consistently over many many years, six to nine months. So the very first question that everybody should be asking is, how is it that somebody can move in your house and be there for nine months and you don't even know they're there? So what's ironic is one of the biggest advantage that attackers have had is they don't actually have to rob your house in three minutes or they get caught. They can live with you for nine months, as they would say, casing the joint, and. Nobody catches them. Nobody calls the police and says, "Hey, we have a problem. By the time they actually do rob the joint, they know everything about your house. They probable more about it than you do in some cases. That creates a disadvantage for the defenders that's almost insurmountable. But unfortunately, that's the real world. Again, that's what the data tells us: is that the dwell time has been measured in months, and sometimes in really bad cases in years where the threat has existed. So back to my comment about what's one of the biggest blind spots we have: we don't even know when something's inside of our environment. Oftentimes, for weeks, months, quarters, or years. Well, if it's in there that long, undiscovered, there's a lot of damage that it's going to be able to do when it decides it's time to do it.
Speaker 2 20:49
Wow, that is fascinating. Thank you for sharing that. I want to talk about Illumio because when you first started the company, microsegmentation wasn't something that was widely understood. What convinced you that this was the right problem to solve? It's
S S
Speaker 1 21:11
probably a combination of a couple or a few things. One, which is absolutely more true today than it was when we thought about starting the company. There's a big problem that needs to be solved, and that problem is giving cyber that second job, second mission. I believed it back then. I believe it to be a many, many, many times more true today. And the AI transition has only, in every sense of the word accelerated my belief that the world needs to have this security control in place. Obviously, my bias and my advocacy will always be that Illumio is the one to put it there. But when I think more big picture and more globally, buy it from us, buy it from our competitors, but don't not have it because it's going to end really badly, and there's a lot of critical infrastructure in the world that needs to be more resilient than it's been in the past. So I think that's sort of number one was the drive to solve what I thought was an important problem, and I would argue is just growing in importance every single day. The second one was, and I'll say this very openly, a complete lack of awareness of how long it was going to take for other people to agree this problem needed to be solved. I don't think that any of us early on in the company's life really thought that there was a well-defined category or market, but I also don't think that if you told any of us that it would be Q4 of 2026 when Gartner puts out the first magic quadrant on network segmentation or micro segmentation, any of us would have believed you. We would have said, "There's no way it'll take that long. People will get it faster. People will deploy it faster. Gartner, Forrester, all of the others will have to cover it faster. And it did take a lot longer than any of us thought, it's not a reason to start or not start a company. But I think we thought it would take time. We didn't think it would take this long. And the third one is just me personally, just complete stubbornness. There were a lot of people along the way who said, you know, this is taking a really long time. I can't believe you haven't thrown in the towel. I can't believe you're not convinced it's never going to happen, and I had the same view that I had in the beginning. It's a big, important problem, and someone's going to solve it. And if they do a really good job solving it, a big, important, valuable company will be built in the process. And one thing that I think is probably consistently true for founders is that we don't operate on the same timelines that others do. It's great when it all happens overnight, and there's no doubt that I don't know anybody would want to start a company and say it's going to take a long time to find its path to becoming meaningful and successful and big. But there's this sort of old expression about you know the overnight success a decade in the making. There's a reason that expression exists because when you read about the success, everything appears to have happened overnight. Most of them do not, and so I stuck with it because I thought it was the right thing to do. I didn't stick with it because there was a timeline that was predefined,
Speaker 2 24:14
despite having an undefined timeline and the market perhaps not being so open and willing and ready to receive this, was there a moment early on where you you know you doubted whether this was something that would be able to come to fruition or it was just a matter of timing? Like, what was your thought process behind that, and what gave you that conviction to keep going, even when the market did not seem ready.
S S
Speaker 1 24:44
I mean, I think I doubted it this morning over my coffee. Still, right? Like, I mean, you know, it's one of those things where it's easy once it's obvious and there, but every second up until then, you're always going to have at least some tiny, tiny, tiny little doubt. I didn't really doubt it. Morning, I promise. But but yes, I mean, if you've been on a journey like this one, where the gardeners of the world that become so important to the validation of both category market as well as company leadership within them, if it takes this long to get there, you are going to have lingering doubts. I think it would almost be, you know, it would almost be impossible not to have them, and so I do think that just acknowledging it, admitting it, being transparent about it, whether it be talking about it in retrospect or to the team along the way, it's super important that I'm comfortable saying that. Yeah, for a long time there was at least a twinge, a tiny lingering doubt of what if it turns out that we're right, but we're not right enough, or what if it turns out that we're right, but it's going to take so long that people won't remain engaged and committed and excited? If you ask me, though, in terms of conviction around being right, eventually, I will tell you, and there's no way to prove it other than getting up and coming to work every single day and remaining passionate and excited. So to the extent that I've done that for a long time, hopefully the evidence is not in what I say but in what I did. I never for one second believed that eventually this wasn't going to become a big important problem that everybody agreed needed to be solved. That has nothing to do with the Illumio story, that was my conviction around the domain, the problem, and I will say to some extent my absolute belief that the large incumbent vendors who could have and should have solved the problem shirked their responsibility and did not focus on solving the problem, and that's where the opportunity was created for Illumio, because if I believed that the problem was going to be genuinely pervasive, very large, by definition that means there would be enormous opportunity around revenue and value creation. If I also equally believe that the large incumbent providers would see that and solve it. That would mean that the fight to be a startup would be very different and potentially a lot harder. I had a lot of conviction around the problem. I'd say absolute conviction. I had a lot of conviction that the incumbents were going to miss the ball, and those two things together, I think, gave me the conviction and the desire and the passion to say, let's go build a company to see if we can go win this thing.
Speaker 2 27:25
You mentioned that Illumio has been recognized by analysts like Forrester's and and gotten a peer insights. What did it take to receive that level of validation?
S S
Speaker 1 27:41
So one of the interesting things about being super early in what isn't even a category yet, let's just say super early in a market with a category potentially to come. That's probably the best way to say it. One of the interesting parts about being on that journey is when you do talk in the earliest of days with the foresters, the gardeners, the analysts who tend to write about and cover these markets, and eventually the categories that come out of them, you are certainly advocating for your story, but you're equally advocating why eventually the mass market is going to care about this. There is no category if the mass market doesn't adopt. There may be a market, but there's not a category. And so, in those early days, we're having conversations with Forrester and Gartner and others that, in some ways, are very similar to how we're talking to early prospects and customers about why they should care about this, and similar to those conversations where evangelizing the problem, and we're advocating for Illumio being the solution specifically, but we're having to do both. And obviously now, when we hear things from Forrester and from Gartner and others, where they tell us that the inquiry volume, the number of phone calls that they're getting from customers asking about segmentation, is going up exponentially quarter over quarter, year over year. As you can imagine, that's very exciting for us because what that does is it removes the need to evangelize to everybody. The customers are already recognizing the problem; they know they have to solve it. What they're now doing is what they do in a normal buying motion. They're saying, "Okay, who are the market leaders? Who should I talk to about partnering and buying something to solve this problem, and that's a very exciting transition. It's also one, as I said, we thought would happen earlier, but we're just thrilled to see it happening now.
Speaker 2 29:50
And one of your more recent launches is Illumio Insights, powered by an AI security graph. What does that platform? Enable organizations to see or understand that maybe they didn't have visibility or understanding of before.
S S
Speaker 1 30:10
It's something that, in a lot of ways, like so many pieces of the Lumio story, I'm so shocked that we didn't figure it out sooner or stumble into it sooner. I'm glad we got there when we did and the way we did, but I look back now and say I can't believe that we didn't think about this more seriously years ago. So the best way to describe it, and it's very simple, and I'll say relatively non-technical, is this: cybersecurity has studied the posture of so many different parts of an organization's infrastructure for so many years. We look at servers. We look at laptops. We look at identity. All of these different things that are all critical pieces of a company's infrastructure and their IT and of course their cyber. And we have tools that look at the posture of how all these things are set up, how they're changing over time, and ironically, the one thing that everybody is basically ignored forever is the posture of the network that connects everything. So when a laptop talks to another laptop, or a laptop talks to a server, or a server talks to something running in AWS or Azure or GCP, it's all talking over networks, and for some reason, and I think the reason is probably because it turns out that the posture of the network is the hardest posture to figure out. But for some reason, we've sort of ignored the posture of the network. I'm not claiming that we have no network visibility, or we've had no network posture understanding. But what I'm saying is, the network is about as critical as anything in the environment, and it is amazing at how, when you look at our understanding of it, how unbelievably bad it's been for so long. What insights did was it took the same security graph that we actually built our segmentation product on, the same foundational platform that we built our segmentation product on, and it recognized that by using AI and observability on top of that graph, there's an enormous amount of no pun intended but insights into the network posture that fall out of that analysis, and once we realized that, we started very aggressively figuring out how to productize that, how to package it, and in January of this year, we brought that product as our second product to market, sitting on top of the same platform, sitting on top of the same security graph that we've always had, but powering it with this AI analysis. And I will say, although we're very early in the journey, six months in the evolution of a product is, you know, it's literally like an hour. But the feedback, both by the way, good and bad meaning. We love this. We need more of that. We love this. We need a better workflow here. The feedback has been fast. It's been furious, and I think we're really on to something. And the teams, literally right outside of that door behind me, are working on building out improving insights in real time, but I think directionally having this understanding of the posture of the network is something that people have been yearning for for a really long time, and I think we're on the right track.
Speaker 2 33:31
And you mentioned that customer voice and feedback plays a major role in in Illumio's evolution in the development of these products, how do you ensure that that feedback actually influences product decisions?
S S
Speaker 1 33:48
So I think there's a couple of mechanical things that you do, and we do them like every I'm sure cyber company, and for that matter, probably every enterprise IT company does. We have things like our customer advisory boards, our technical advisory boards, our cabs, our tabs, we do QBRs and EBRs every quarter or a few times a year with some of our customers in order to spend time really understanding what's working and what's not. So I describe that as those are mechanical things that you put in place to make sure that the feedback loop is constant, and that it's continuous, and that it's regular. I will also note, though, because I do think that this is a little different when you're on a journey like ours. If we had decided that we were going to start a company that builds firewalls 10 years ago, or we decided we were going to build a company that builds endpoint protection, like CrowdStrike, 10 years ago. Those companies in those categories are building into categories that are already very large, very incom. Been very mature. It doesn't take anything at all away from the innovation that they do, or the fact that they're able to build new and innovative things that those categories never had in the past. But there is a baseline because even 10 years ago, almost every company and government organization around the world had firewalls deployed already, and most of them for decades, not years. So you have a really mature understanding of the environment that you're walking into and the category that already exists. When we started, most customers on the planet had never even heard of segmentation. Almost nobody had it deployed, so that feedback loop wasn't how do we build a better version of what you're already doing. It was we're building something brand new that none of you ever ever even heard of. By the way, most of you haven't even thought about solving this problem yet. We need your feedback all the time. We don't even know directionally exactly where it goes. Now we have a point of view, which is why we started the company. So we're not relying on you to tell us what to build. We had a point of view, and that's what got the company started and what became the first version or MVP of the product. But from the moment we deployed the first piece of software and the first customer, everything became continuous learning after that, and so we do talk a lot about how we have the voice of the customer in the room all the time, and I do think that when you're building a technology into a category or market that's very new, very nascent, doesn't even exist, you don't have a choice. If you don't build with the voice of the customer as a north star, you are much more likely to get lost than you are to find the right place to go.
Speaker 2 36:45
I want to talk about innovation because many founders talk about innovation, but balancing innovation with financial resilience and making commercially viable decisions is an entirely different thing. I'm curious to know how have you approached that that balance as a CEO.
S S
Speaker 1 37:08
So I say all the time that I think the CEO ultimately only has a couple of, I'll say, really important jobs that are specific only to the CEO. I think our biggest job is without a doubt to be player, coach, helper, inspiration in any and all forms, anywhere we can, any part of the company, any day of the week. So I want to be pulled into what I can help with and pushed into what I can be helped with. I do think that one of the few responsibilities that the CEO does hold is obviously the financial viability of the organization, and obviously as the company gets bigger, your partner in that is your CFO, and obviously the team that works with your CFO. But ultimately, if the company were to go broke unexpectedly, hard to imagine, but if it were to happen, I believe that the responsibility for that ultimately solely rests with the CEO, and so I think the CEO has to have a point of view on what part of your journey are you on, and therefore what is the balance between innovation investment. So I'll give you an example that is not applicable to Illumio. It's hard to imagine an AI startup right now in 2026 not spending at all costs. I don't think you're going to find a lot of AI startups that say, "Let me tell you how I'm balancing my fiscal responsibility, and the reason for that is twofold. It feels very much like an arms race, which means going faster and spending more becomes part of the operating model. And to be fair, it seems like never-ending funding at almost any valuation that somebody can come up with. So when the game on the field is being played with those rules, your job as CEO is to set a strategy that plays the game that is on the field. In our case, there was a point in time where we felt like we were operating in that way. We were raising often. We were spending aggressively, mostly on innovation, and in the early days, getting to market, we were definitely not looking at things like cash flow and profitability as any kind of short-term goal that we had to think about. Now, fast forward to 2026, where 1000 or so teammates all over the world hiring in every team and department across the company. We've had accelerating growth at scale for years. We haven't raised capital in almost five and a half years. We're running the business in a different way today. We're certainly not running it like a slow growth, low growth company. Accelerating growth, hiring all over. But we're doing it with the ability to now balance the revenue, the gross margins, and thinking about what does that total story look like, and so I think that there's sort of a shift in how you think about your journey over time based on where you are in the journey, and and for us one of the things I remember so often, some of our investors in the early days saying to me, "You know, there's going to be this this thing down the road, years ahead of you, where you're going to want to be in control of your own destiny, and I never understood at all what it meant, and I certainly didn't care one bit why they were saying it to me. Five plus years after our last round of funding, and with at least right now absolutely no plans out of necessity to need to raise capital again, I completely understand what controlling your own destiny means. And when markets are going up and to the right and everything is great, nobody cares. The minute that fundraising gets harder, valuations correct, and it wasn't all that long ago that we went through the last cycle of this. You start to realize how valuable an asset it is when you're growing, scaling, and you don't need to ask anybody for money to do it.
Speaker 2 41:11
This leads me to a question I've been wanting to ask you because you-I heard you once say you had a mentor tell you once. What gets you here doesn't always get you there. Talk to me about that and how that concept has shifted the way you approach leadership.
S S
Speaker 1 41:34
Yeah, I actually just had dinner with that particular mentor a couple of weeks ago, and we were talking about a whole bunch of these things, and the hardest thing in the world, I think, for a leadership team, it's not just the CEO's responsibility. I think the hardest thing in the world for a leadership team to do is to question, and certainly question hard enough when things may be in a place where they're not going to get you to the next phase, the next leg of the journey. I sort of describe it as when things are going awesome, you almost don't want to ask questions. You just want to ride the rocket. When things are going really terribly, whether you want to ask the questions or not, someone's going to start asking the questions. And if it's not the leadership team, I promise you, eventually the board will. So at the two extremes, it's sort of like the answer's obvious. The hard thing is when things are going well-not rocket ship well, but they're going well. There's no debate that they're going up to the right in the correct direction. It's it's hard sometimes to walk in and say, I sort of feel like we're going to get to a point where they're going to stop going well, and I want to ask the question now before that happens. While I still have the luxury of time on my side and hopefully money in the bank to be able to sort of say why is that? Is it a product problem? Is it a go-to-market problem? And of course, the hardest one by far is is it a people problem? I think companies go through this. I think a lot of times it's not necessarily talked about as openly as it should be. I don't think it should be a surprise because a startup moving into a larger startup into a growth stage company is not really one company. It's almost like you're stapling a few versions of the company together. When you're a large and mature company. The growth rate slows. I'm not saying that means that things get easy. It never does. But there is a steadiness and predictability that does start to seep in, and there's an advantage to that. The disadvantage is when you get too comfortable with it. But I think when you go through these step functions, it's not a surprise that some of the folks that were unbelievably great for one step are not necessarily the right folks for the next step. And by the way, it's not just the company deciding that or the CEO deciding that. I think sometimes they know that they're not going to enjoy the next step. It's always hard to have that conversation, but there is no doubt about it that you can't avoid it, and when you do, what ends up happening is people end up in a job that they're not good at or comfortable in. They end up unhappy because nobody wants to be in a job where they feel like they're failing. It's not a happy place for anybody, and so I do think the one place where the CEO has a fairly unique responsibility. Is you have to force those hard conversations to the table, if they're not happening organically, and a lot of times they don't, especially when a team really enjoys working with each other. But your job, your responsibility is, I say this at Illumio all the time, and I know I'm not alone. I'm sure I stole it from somebody a lot smarter than me. Company, team, individual, and it is always in that order. If it works for the individual but not for the team, that's a problem. And if it's working for a team but not for the company, that's a problem. It has to be company, team, individual in that order. So forcing these conversations about why was this team. Performant for the last two years, but now something's not working. Or why was this person amazing for the last five years, but now for some reason it's not clicking? And you can tell you have to have those conversations.
S
Speaker 2 45:12
There's so much wisdom in what you just shared, and I'm so glad that I asked the question because I think business, by nature, is cyclical. Markets are cyclical, and something that you touched on, and particularly being a company that's been in the industry for more than a decade now, I'm sure you've seen, you know, certain markets that you've navigated, which have been really good markets and some more challenging ones. What is it that's really helped you to stay committed through all of the seasons, through all of those cycles.
Speaker 1 45:46
So, if we go back to the thing about wanting to solve a big important problem, if you really think you're making a dent and moving the needle, it's hard not to continually be inspired by that. You need the numbers. You need a path to success. You need to feel like you're moving forward in the journey. And by the way, I will say, as CEO, obviously I want and need that for myself. But much more so, I need to believe that the team feels that it doesn't matter how committed I am if I can't, as they say, rally the team around that same cause and have them take that same inspiration. I'm pretty sure I can't do it alone, which means I need every one of these folks to be as excited about it as I am. Now, as a founder, you may have a unique perspective. Maybe your perspective has a longer arc than some of the other folks, but you need passionate, committed people in the tent every day. Otherwise, you can't get there. Period. So the problem solved, moving the needle, working on something important-all those things kind of become table stakes. I do think, and I don't have any problem admitting it. For me personally, I have to believe that we're going to win, and let's be very clear that winning comes in two forms. One is solving a big important problem for the world. I don't. I didn't want to work on something that I didn't perceive to be really important, which has nothing to do with the financial success of the company, size, scale, valuation. Like I really love the fact that when our customers deploy us, I hear the stories afterwards, and I'm like, we're moving the needle for them on something that nobody else has been able to move the needle on in the past. And so there's a lot of excitement and passion and inspiration. But I also want to fully give equal credit. I never intended to start a company to to be a part of a team of 20 people. From the very beginning, this was about building a big, important, meaningful company-one that grew up, had 1000s of employees, was able to raise the money necessary to make the investments that we did. Eventually, not need to raise money to be able to grow at scale, to be able to eventually go public, to be able to monetize all the work that all these folks have done over the years. The investors who believed in us and the teammates who come to work every day, I don't want to pretend that one without the other in either direction would work. The big important problem is inspirational, and if you do a better job than anybody else solving it, you are probably in the best position to build something big, important, and valuable for all of the stakeholders who come to work and make it happen. So for me, it was both. From the beginning, it was number one, and then every day after that, it became now. Can we become the market leader in solving this huge problem? And if we focus on that and that alone, all the other outcomes that are important to us over time will follow.
S S
Speaker 2 48:59
It certainly sounds like knowing your purpose and the problem that you were setting out to solve from the beginning, and having that conviction is something that's really enabled you to have so much longevity with what you do. What I'm curious to know, though, is how has your leadership style evolved from those early days being a startup founder to now being the CEO of a global cybersecurity company.
Speaker 1 49:27
So I think there's two answers to that, and they are definitely discreet. The first one is I definitely believed it back then. I believe it now. I think you have to be very clear about the difference in being. There are words that people use like honest and transparent and open. I think there's a different word and one that, for me, has always been sort of the most important one, and it hasn't changed one iota, at least from where I'm sitting, which is authenticity. I am a kid from Brooklyn, New York. Who grew up in the New York metropolitan area with everything that comes with that? Usually, it involves some version of like pizza, bagels, and being too blunt for your own good. I was that way when we started the company. I'm pretty much still that way today. A little less pizza and a little less bagels nowadays, but every bit is blunt. And when people join Illumio and I get to meet them for the first time, either before they join or after they join, I'm still as blunt and transparent and authentic and open as I've ever been, because that's my authentic self, and I don't want to change that. I think that each one of us has a personality that we bring to the table, it's part of what makes you you professionally and personally, and you shouldn't try and disguise that, hide it, morph it over time. So I think that's one answer, and on that one, I hope I never drift. I absolutely will admit the discreetness is the second answer. There is a difference in getting up at an all hands or a town hall with 1000 people all over the world, and making sure that your tone, your tenor, the examples that you use become more broadly understandable, broadly applicable. I know it sounds so funny, and it's such a tiny example, but recognizing that not everybody is sitting in Sunnyvale, so when we start in all hands, it's not good morning because it's 10 a.m. at the building in Sunnyvale. It's good morning to all of you here, and good evening to those of you that are joining from Europe, and really good night to those of you in Asia who are kind enough to join. Realizing that as the company grows, your tone, your ability to communicate and make things consumable and understandable-it does have to change with the company over time, and so it's a deliberate effort to make sure that you're thinking about the audience, the team, the people. By the way, same with customers meeting with a bank in New York and meeting with a bank in France, we may be talking about the same software, but we're having very different conversations. And certain things that we talk about culturally are different. So I think that as the company's grown, as our footprint in all ways have grown, I have to make an investment and an effort to be comfortable being one of the leaders of the company in those situations that now span a lot more than Sunnyvale or Sunnyvale in New York, and you should want to make that investment. You should want the customer in Singapore to be as excited and comfortable with you sitting there as the one in New York, but knowing you're going to have probably two different conversations, and the same with the team all over the world.
S S
Speaker 2 52:45
Andrew, I want to ask you: There's leaders that are listening to this podcast right now who operate outside of cybersecurity industry. What lessons from your journey do you feel you could really share with those leaders that are listening that would apply to leadership more broadly.
Speaker 1 53:05
Look, I think we just touched on for me what is the single most important one, and I'm not saying it's the only one, but it's the most important one. You are who you are. I'm sure there are lots of people who do decide that their authenticity takes a back seat to whatever it is that they feel they have to do in order to be successful, and I'm not encouraging or discouraging that. I just think that there is, especially in today's world, things are complicated. It's very hard to obviously know a lot of what we're seeing and what we're hearing and what we're reading and what's popping up on our phones, what's true and what's not. There is just an enormous premium in my mind to authenticity because it's one of the few things that you have absolute control over. So to me, that's that is a very very important part of I think an entrepreneur or CEO founder's journey. I think this this notion of you ultimately have financial responsibility for the well being of your company. It's super easy when things are heady like they are right now in certain parts of the world to sort of just pretend it's going to go on forever. It never does. There's always an unexpected twist, curve, downturn. Markets do move in cycles. They always have. I don't want to say they always will because I don't have a crystal ball any better than anybody else. But the evidence so far is for every up, there's a down. Your job is to be thinking about all those things, but I definitely would say the one thing that we haven't touched on, it just hasn't been part of the conversation. But it's something that I'm definitely telling myself now over the last let's say six to 12 months. I think that the number one thing that we're all going to have to get ready for is we're going to re-rate the definition of speed, and I don't think it's going to matter if you are a 12-person startup, 1,200 people, or 120,000 employees, because we're seeing it happen to the biggest of the big. And I think in startups and I'll say smaller growth stage companies, we sort of take it for granted. But I don't think we're going to be able to anymore. We are going to re-rate what the world defines as speed, because no matter what you believe the future of AI is or isn't, to the extent that what's here is here today, it moves at machine speed, and the pressure to not be left behind, the pressure to make decisions quickly, decisively, and without the benefit of perfect information, we've had this enormous luxury of being able to spend a year thinking about things in the past. But it isn't because we necessarily should have, or because we got better answers. It's because our competitors were spending the same year doing the same thing. We're going to break that model. It's some of it's breaking, obviously already, and I just think we're going to have to rethink what the word speed means.
S S
Speaker 2 55:48
Andrew, here at CEO Behind the Scenes, we do have a closing tradition. We love to wrap up all of our interviews with the same two final questions. So the first question I wanted to ask you: Is what is one thing you've changed your mind about recently, and why?
Speaker 1 56:07
One thing I've changed my mind about most recently is that any of us have a true handle on what the ROI is on our AI investments. We're seeing the stories come out. I'll say some of the cracks in the armor around tokens getting consumed, where five months into the year the entire budget is already gone. I think we had a view on what we were spending all this money on, and I think for the first time, sort of like breaches where we got okay admitting they happen, companies are no less excited, but for the first time, it's getting okay to say, spending a lot of money on this, and I'm not exactly sure what I'm getting for it yet. I've changed my view on how long it's going to take to get to crisp, clear math. I think it's going to take longer than any of us thought.
Speaker 2 56:58
Okay, question two is: What is one thing that you've not changed your mind about? A belief that you'd want to share to help others lead or live better.
Speaker 1 57:11
Okay, corporate answer first, which is that in cyber resiliency and recovery are about to become the single most important piece of everybody's cyber posture, AI is going to drive us there faster than we ever imagined. More generally, to live better, enjoy the journey. I've never ever changed my mind on that. It's been a long one, as we talked about, longer than I knew when I started. Enjoy it. There are going to be wild ups and wild downs. You're going to have really good days, and you're going to have some pretty crappy ones. Just enjoy it. We're all incredibly lucky to be working on interesting things that matter a lot. Remember that and enjoy the journey. My view on that hasn't moved one millimeter or inch since the day we started.
Speaker 2 58:00
Andrew, I've so loved and enjoyed our conversation today. We have covered so much ground, everything from cybersecurity to resilience to changing markets and changing customer expectations to leadership. This has been such a joy and privilege to have you on the show today. Were there any final words that you'd like to leave our audience with today before we wrap up.
S S S S S
Speaker 1 58:23
Well, first, thank you for having me, and it's been an absolute pleasure. And my final words are: go faster.
Speaker 2 58:30
Very well said. Thank you so much, Andrew, and to our audience, thank you so much for listening. If Andrew's insights were valuable to you, and if you know that there are people in your network that would really benefit from everything that he so generously shared today, please be sure to subscribe, rate the show, and share it with someone that you know. Thank you so much for joining us, and we'll see you next time on CEO Behind the scenes.