0:00
/

Venturing into Industrial Cybersecurity: AI, Adoption, and Scale

A chat with Vincent Berk, Partner at Apprentis Ventures

Welcome to the 129th edition of Deep Tech Catalyst, the educational channel from The Scenarionist where science meets venture!

This week, I sat down with Vincent Berk, Partner at Apprentis Ventures. We explored how AI is broadening the software-builder base and reshaping cybersecurity, why domain expertise is becoming increasingly important as software moves into specialized industries, what creates a defensible moat when products are easier to reproduce, and how founders should think about team composition, technical validation, enterprise sales cycles, and focused go-to-market execution.

Key takeaways from the episode:

🤖 AI is accelerating both software creation and vulnerability discovery

AI allows more founders and domain experts to build software, but the growing volume and speed of development also create more potential failure modes. At the same time, AI can help identify vulnerabilities more quickly.


🎯 Domain expertise is becoming a cybersecurity advantage

Security depends on understanding how a system should behave, what should be allowed, and where failures can occur. As software becomes more specific to individual industries, founders with deep knowledge of those operating environments may be better positioned to identify risks and build focused cybersecurity solutions.


🛡️ The strongest moats are built around process, problem, and people

When software is easier to build, features and algorithms alone become less defensible. Durable advantages are more likely to come from proprietary operational knowledge, a deep understanding of the problem that competitors cannot easily replicate, trusted customer relationships, and the ability to make a solution work at real enterprise scale.


📈 Cybersecurity go-to-market is a land-and-expand process

Customers rarely adopt an early-stage security product across the entire organization immediately. Founders must plan for limited initial deployments, and long validation cycles. Success depends on targeting a precise buyer, earning trust directly, and concentrating resources where that buyer already gathers information and validates new solutions.


DeepTech Briefing

The New Route to a Seed Unicorn | Deep Tech Briefing 120

The New Route to a Seed Unicorn | Deep Tech Briefing 120

Independent intelligence for deep tech allocation and industrial strategy.


BEYOND THE CONVERSATION — STRATEGIC INSIGHTS FROM THE EPISODE

AI Is Expanding Both the Cybersecurity Surface and the Builder Base

Artificial intelligence is changing cybersecurity in two opposite directions.

  1. On one side, it is making software easier to build. Founders, operators, and industry experts can now create applications faster, even when they do not come from traditional software backgrounds. This is especially relevant in industrial and highly specialized markets, where the most valuable opportunities are often understood by people with deep domain expertise rather than by generalist software teams.

  2. On the other side, the rapid expansion of software is increasing the number of systems that must be protected. A company builds software, someone finds a vulnerability, and another company develops a way to detect or mitigate it. AI does not change that fundamental dynamic, but it simply accelerates it.

More software means more vulnerabilities

AI can support high-quality software development when it is used inside disciplined engineering processes. But companies are also producing more code under tighter timelines, with growing pressure to launch and iterate quickly.

The issue is not simply whether AI-generated code is better or worse. The deeper problem is volume. More software means more applications, integrations, permissions, and potential failure modes.

The concern is therefore not only the quality of individual applications, but the expansion of the software base. When tighter development timelines contribute to lower software quality, the security risk increases further.

Authentication failures, poorly designed permission systems, and unexpected software behavior can all become entry points. As software becomes more embedded in industrial operations, vehicles, infrastructure, and physical systems, those weaknesses can affect more than data. They can affect how the underlying business operates.

AI accelerates vulnerability discovery

AI is also making it faster to search for weaknesses.

A security researcher can inspect software, test common failure modes, and look for vulnerabilities. AI can perform many of the same activities at much greater speed. It may not always be better than an experienced expert, but it can repeat analytical processes across far more code and far more systems.

This increases the overall capacity to search for software weaknesses and accelerates the ongoing cycle of software development, vulnerability discovery, and the creation of new detection and mitigation methods.

The result is a much larger effective workforce capable of searching for weaknesses. Vulnerabilities that might previously have remained undiscovered for longer can now be identified more quickly.

This makes cybersecurity increasingly relevant across a growing range of industries, particularly as AI becomes more deeply integrated with the physical world.

More specifically, as software becomes easier to create, it is moving deeper into sectors that were previously less digitized. Security depends on understanding how a system is supposed to work, what should be permitted, and what kinds of failure are possible.

In increasingly specialized software markets, that knowledge often comes from direct industry experience. Therefore, the people who understand those sectors may be particularly well positioned to become cybersecurity founders.



Domain Expertise Is Becoming the New Entry Point

Cybersecurity is often treated as a field reserved for founders with deep technical backgrounds. That assumption is becoming less reliable.

As AI lowers the barriers to building software, founders with strong industry knowledge can move closer to product creation. They may not have spent years writing code, but they understand how a specific process, system, or market is supposed to work.

That knowledge matters because cybersecurity begins with failure modes.

A security problem emerges when a system behaves in a way that should not be possible. An authentication process fails. A permission is too broad. A piece of software accepts an unexpected input. A device communicates with something it should not trust.

To identify those risks, a founder needs more than general technical ability. The founder needs to understand the operating model behind the system.

Security is embedded in the domain

Every cybersecurity solution is built around an implicit model of normal behavior.

To protect a system, a company must know which actions should be allowed, which should be restricted, and what kinds of behavior indicate that something has gone wrong.

In highly specialized industries, those answers are often not obvious to outsiders.

A founder who understands a particular industrial process may be better positioned to identify domain-specific failure modes that outsiders may not immediately recognize.

The same principle can apply across traditional industries, industrial operations, IoT systems, and connected vehicles.

As software becomes more specific to individual industries, security is likely to become more specific as well.

The market may therefore produce more point solutions: focused products designed to address a particular failure mode, workflow, or operational environment rather than broad platforms attempting to secure everything.

This specialization reflects how software itself is evolving. Bespoke applications can create equally specific security requirements and failure modes.



The New Moats in Cybersecurity

As software becomes easier to build, defensibility becomes harder to prove.

A product may be technically impressive and still become easier to reproduce as software development becomes more accessible. General technical knowledge alone is therefore less likely to provide a durable advantage.

A useful way to frame defensibility is through three elements: process, problem, and people.

Process, problem, people

A process moat comes from knowing how to discover, detect, operate, or solve something in a way that is not obvious from the outside.

A problem moat comes from understanding how a complex system behaves in the real world. This often requires substantial experience with the specific conditions, constraints, and failure modes of that environment.

A people moat comes from trusted relationships. Early-stage products are rarely perfect. Founders need customers who are willing to test incomplete solutions, provide feedback, and tolerate mistakes. Access to those first users can create the initial validation that a startup needs before the market is ready to trust it more broadly.

This is why relationships within a specific industry can be strategically important. They can provide the early access and trust required to test a product, make mistakes, and validate the initial solution.

Real-world performance is a critical test

One of the first differentiators to examine is also one of the simplest: whether the product works outside the lab.

Many cybersecurity solutions are convincing in concept. They combine data sources, identify a suspicious pattern, and appear capable of detecting an attacker.

The difficulty is whether the same approach works inside a real enterprise.

Networks are larger, more fragmented, and more complex than test environments.

A system may perform well on one computer or a small dataset and fail when it must analyze vast numbers of devices, identities, data streams, and connections.

As in the physical world, scalability is therefore part of defensibility.



Team Composition and AI’s Limitations

The quality of a cybersecurity startup depends not only on its technology, but also on the composition and dynamics of its founding team.

At the pre-seed stage, the ideal team is usually small. The conversation suggested a founding team of more than one person and, ideally, no more than three.

However, what matters most is not the number of people. It is how well they work together.

The founders should know one another well enough to challenge assumptions, expose weaknesses, and disagree without damaging the relationship.

They should be able to call out one another’s flaws while maintaining enough focus and trust to work effectively together.

Strong founding teams often combine 3 capabilities.

  1. The first is imagination. A team can benefit from someone capable of seeing possibilities beyond the current product: new applications, larger markets, and different ways the technology could evolve.

  2. That energy must be balanced by execution. Another member of the founding team needs the executive discipline to reduce the number of possibilities and return the company to its immediate priorities. The team may see ten interesting directions, but it still needs to decide which customer, problem, and market it is building for today.

  3. The third capability is domain expertise. At least one founder should understand the industry and the problem deeply. This has become more important as software development has become easier. When the ability to build is less scarce, the quality of the problem insight becomes more valuable.

At its core, technical capability alone is not enough. The team also needs to understand the market it is entering and the specific problem domain in which the product must operate.

AI is powerful, but not universally effective

The same discipline is required when evaluating the role of AI inside the product.

New technologies often appear capable of solving almost any problem before their limitations become visible. AI is still passing through a similar phase.

It is remarkably effective at generating language, knowledge, and code. It can compress a large amount of information into a relatively small model and produce useful output across many different subject areas.

Cybersecurity, however, often depends on a different type of reasoning.

A security system may need to connect a series of failed login attempts with a later successful login, determine whether those events are related, and compare them with behavior across other machines, users, and applications.

That becomes difficult when the events occur far apart in time or across different data sources.

An experiment may work across three controlled data streams. A large enterprise may contain hundreds of thousands of data streams generated by computer systems, identities, and pieces of software.

The technical challenge is not merely identifying an unusual event. It is correlating disjointed events across time and across systems at enterprise scale.

This is where many AI-based cybersecurity products face their real test.

A compelling demonstration may rely on a novel prompt that works in a controlled laboratory environment. That does not prove the solution can identify the same patterns inside a complex enterprise.

Investors therefore tend to look beyond the “AI layer”. The central question is whether the founders have solved the core problems of correlation and scale within their particular problem domain.

AI can help founders build software faster and can assist in developing algorithms to address these problems. But it does not remove the need to understand the underlying architecture of the problem.

The more credible cybersecurity startups are therefore likely to combine an effective founding team, deep knowledge of the problem domain, and a realistic understanding of what AI can and cannot do.



Cybersecurity Go-to-Market Strategy

A technically strong cybersecurity product does not become a scalable company simply because the problem is real.

Adoption is slow because customers rarely deploy a new security solution across the entire organization from the beginning. They start with a limited test.

They want to know whether the product solves the problem, whether it works inside their environment, and whether it continues to perform as usage expands.

Only after those questions are answered does the customer buy more.

This is the logic of land and expand.

A startup enters through one site or another limited deployment, then grows after the product has demonstrated that it works and scales.

Founders need to reflect this reality in their financial planning. Even when the product works and scales, it may take 12 to 18 months before the company begins to see meaningful traction.

The ideal customer profile must be narrow

Cybersecurity founders can easily begin with an unfocused assumption: everyone has the problem, so everyone can be a customer.

That may be broadly true, but it is not focused enough to support an effective go-to-market strategy.

A startup needs a precise ideal customer profile and a clear understanding of the individual buyer inside that organization.

The company should know who owns the problem, how it will earn that person’s trust, and how it can get in front of the same buyer repeatedly.

Without that focus, the message becomes too broad to attract anyone in particular.

Customer size also matters. Selling to a small company can take as long as selling to a large enterprise because both customers will want to test whether the solution works and scales before expanding its use.

The difference appears after the first deployment.

A small customer may have limited room to expand. A large enterprise can roll the same product out across more locations and at a much greater scale. The initial sales effort may be similar, but the economic opportunity within the larger customer can be significantly greater.

This makes customer selection part of the business model.

Partners cannot replace founder-led sales

Another common assumption is that a reseller or systems integrator will solve distribution.

The logic appears attractive. The partner already has customers, so it should be able to add the startup’s product to its portfolio and generate sales.

In practice, large integrators may already carry vast numbers of products. They have little incentive to invest time in understanding an unknown solution unless they believe it can generate meaningful volume.

The vendors most likely to receive that attention are usually the vendors that are already large.

An early-stage startup should therefore retain control of its initial go-to-market rather than assuming that a partner will create demand and sell the product on its behalf.

Partners may play a role, but founders should not expect them to create the company’s initial traction.

Precision marketing over broad visibility

The same discipline applies to marketing.

Broad brand marketing is a weak substitute for a focused strategy built around a defined ideal customer profile and buyer persona. Trade shows, advertising, public relations, and sales development are only tools.

Their value depends on whether they reach the person responsible for the problem.

The more useful question is not what percentage of the budget should go to marketing. It is whether the company is “shotgunning or sniping.”

A broad outreach approach begins with a generic budget allocation. The company buys ads, attends large conferences, and hires sales representatives without knowing precisely where its target buyer spends time.

A precision approach begins with the target buyer.

The founder identifies the person responsible for a specific security issue inside the type of company the startup wants to serve.

The next step is to understand where that person reads industry news, exchanges ideas, attends meetings, and builds trust with peers.

Sometimes the right channel will be a focused conference. It may instead be a smaller industry group, a standards meeting, a technical community, or a specialized publication.

The most valuable environments are often those in which buyers validate products among themselves.

A cybersecurity company may begin winning customers inside one vertical not simply because the product appears suited to that industry, but because the security professionals within that vertical know one another, meet regularly, and create internal validation.

Once that pattern becomes visible, the company can focus on the places where those conversations happen.

The marketing budget should follow that insight.

Travel, events, articles, advertising, and sales development should be selected according to their ability to reach a known buyer.

If the company cannot identify that buyer with precision, it has probably not completed enough market research.

A realistic financial and go-to-market model should therefore account for long sales cycles, focused customer selection, direct access to the buyer, and the gradual economics of land and expand.


Scaling & Industrialization

Should we build a factory?

Should we build a factory?

5 strategic steps for deciding what to build, what to outsource, and what to delay.


Disclaimer
Please be aware: the information provided in this publication is for educational purposes only and should not be construed as financial or legal advice or a solicitation to buy or sell any assets or to make any financial decisions. Moreover, this content does not constitute legal or regulatory advice. Nothing contained herein constitutes an offer to sell, or a solicitation of an offer to buy, any securities or investment products, nor should it be construed as such. Furthermore, we want to emphasize that the views and opinions expressed by guests on The Scenarionist do not necessarily reflect the opinions or positions of our platform. Each guest contributes their unique viewpoint, and these opinions are solely their own. We remain committed to providing an inclusive and diverse environment for discussion, encouraging a variety of opinions and ideas. It is essential to consult directly with a qualified legal or financial professional to navigate the landscape.

Ready for more?