'''# My Controversial Take on AI Security Tools
I lost sleep over AI security for months. Waking up in a cold sweat, thinking about the millions of ways our systems could be compromised. We were building the future with AI, but it felt like we were building it on a house of cards.
Everyone is talking about AI security tools. A whole new cottage industry has sprung up, promising to solve all your problems with a fancy dashboard and a big price tag. But I'm here to tell you that 99% of founders are getting it wrong. And I learned that the hard way. ''' '''
The RemoteTeam Nightmare
Back when we were building RemoteTeam, we were obsessed with product-led growth. We wanted to make it as easy as possible for people to sign up and start using the product. But that also meant we had a giant target on our back. We were dealing with payroll data, PII, all the good stuff that hackers love.
We tried all the off-the-shelf security tools. We had firewalls, intrusion detection systems, you name it. We spent a fortune on them. And you know what? They were mostly useless. They were like having a security guard who only checks for invitations at the front door, while the back door is wide open. The alerts were constant, a flood of false positives that made it impossible to see the real threats. It was a classic case of "alert fatigue." We were drowning in data, but starving for wisdom.
I remember one particular incident that still gives me chills. We got a call from a customer who said their data was showing up on the dark web. My heart sank. We spent the next 72 hours in a war room, with our entire engineering team trying to figure out what happened. It turned out to be a sophisticated phishing attack that targeted one of our junior engineers. No amount of fancy security software could have prevented that. It was a human problem. '''
The Epiphany: It's Not About the Tools
That incident was a wake-up call. It forced me to rethink everything I thought I knew about security. I realized that we were so focused on buying tools that we had forgotten to think about the actual problem. We were playing defense, when we should have been playing offense.
I started talking to other founders, and I realized that everyone was making the same mistake. They were all buying the same expensive tools, and they were all getting the same mediocre results. It was a giant echo chamber of security theater.
The turning point for me was a conversation with a grizzled old-school hacker. He told me something that has stuck with me ever since: "You can't buy your way to security. You have to build it into your culture."
That's when it clicked. The problem wasn't the tools. The problem was us. We were treating security as an afterthought, a checkbox to be ticked off. We weren't thinking about it from first principles.
The So-Called "Simple Trick"
So what was the "one simple trick" I mentioned in the excerpt? It wasn't a new piece of software or a magical AI algorithm. It was deceptively simple: We made every single person in the company responsible for security.
That's it. No silver bullet. Just a fundamental shift in our culture.
We started by doing the following:
- Security training for everyone: And I'm not talking about those boring, once-a-year compliance videos. We created our own training program, full of real-world examples and interactive exercises. We made it a part of our onboarding process, and we did it every quarter.
- Red teaming exercises: We hired ethical hackers to try and break into our systems. And we didn't just do it once. We did it continuously. We made it a game, with bounties for finding vulnerabilities. Our engineers loved it. They started thinking like hackers, and that made our defenses ten times stronger.
- Security champions: We created a program where engineers could become "security champions." They were our eyes and ears on the ground, embedded in every team. They helped their teammates make better security decisions, and they were the first line of defense against threats.
It wasn't easy. It took a lot of time and effort. But it was worth it. We went from being a company that was constantly putting out fires to a company that was proactively preventing them. Our security posture improved dramatically, and we were able to sleep at night.
So, What About the AI Security Tools?
This brings me back to the current craze around AI security tools. I see history repeating itself. Founders are throwing money at shiny new tools that promise to detect AI-powered phishing attacks, secure their large language models, and prevent data leakage. And just like before, they are missing the point.
An AI security tool is only as good as the culture it's deployed in. You can have the most advanced model in the world, but if your engineers don't understand the basics of secure coding, or if your employees are clicking on every link that comes their way, you're still vulnerable.
The fundamental problem is that AI introduces a whole new attack surface. It's not just about protecting your network anymore. It's about protecting your models, your data, and your users from a new generation of threats. And you can't do that with a tool alone.
I've seen so many startups get this wrong. They buy a tool, check the box, and then get a false sense of security. They think they're protected, but they're just waiting to be the next headline.
My Advice: Stop Buying, Start Building
So here is my controversial take: stop shopping for AI security tools. At least for now.
Instead of spending your first hundred thousand dollars on a fancy AI-powered security dashboard, invest it in your people. Hire a great security engineer. Build a strong security culture. Teach your team to think like hackers.
I'm not saying that all AI security tools are useless. Some of them are incredibly powerful. But they are a force multiplier, not a substitute for a solid foundation. They are the cherry on top, not the cake. And if you don't have the cake, the cherry is just going to fall on the floor.
As an investor, when I see a founder bragging about their new AI security tool, it's a red flag for me. It tells me they are focused on the wrong thing. I'd rather see a founder who can tell me about their security training program, their red teaming exercises, and their security champions.
Don't be the founder who builds a beautiful skyscraper on a foundation of sand. Build your security culture first. Then, and only then, should you start thinking about the tools.
Your P&L will thank you. Your customers will thank you. And you'll finally be able to get a good night's sleep.
Let's Get Technical: The Adversarial Attack You're Not Ready For
Think about how your new AI-powered customer support bot works. It's trained on a massive dataset of your internal documents, support tickets, and chat logs. It's a goldmine of sensitive information. Now, what if I told you that a hacker could trick that bot into revealing your trade secrets with a carefully crafted prompt?
This isn't science fiction. It's called an adversarial attack, and it's one of the biggest threats in AI security today. The fancy tools might detect some of the common attack patterns, but the truly sophisticated attacks are subtle. They look like normal user queries. A tool can't tell the difference.
Here’s a real-world example. A company I advise, a fast-growing fintech startup, had a state-of-the-art AI security tool. They were confident they were protected. But a red team we hired was able to extract their entire customer list, including contact information and transaction history, by having a series of seemingly innocent conversations with their support bot. The prompts were designed to slowly nudge the model into a state where it would start leaking information. The tool didn't flag a thing.
How do you defend against that? You can't just install a patch. You need a team that understands how these models work at a fundamental level. You need engineers who can build in defenses from the ground up. You need a culture where everyone is thinking about how the systems they are building can be abused.
This is what I mean when I say you need to build security into your culture. It's not about having the best tools. It's about having the best people. People who are paranoid, who are creative, and who are constantly trying to break things. That's your best defense.
An Investor's Perspective: Where I Put My Money
As an angel investor in over 200 companies, including some of the biggest names in AI like Anthropic, OpenAI, Scale AI, and Hugging Face, I see hundreds of pitches a year. And I can tell you that the way a founder talks about security is a huge indicator of their potential for success. The ones who get it right are the ones who are obsessed with building a resilient organization, not just a cool product.
I look for founders who have a healthy dose of paranoia. The ones who are constantly thinking about what could go wrong. They don't just have a security slide in their deck; they have a security mindset woven into the fabric of their company. They can talk about their security training, their incident response plan, and their philosophy on responsible disclosure.
On the flip side, I'm immediately skeptical of founders who lead with the security tools they've bought. It's a classic case of a bad workman blaming his tools, or in this case, a naive founder thinking a tool can solve a people problem. It shows a lack of deep thinking about the problem. It's a shortcut, and in the world of security, shortcuts lead to disaster.
I've passed on deals where the product was brilliant, but the security culture was non-existent. And I've invested in companies with a less-developed product but a world-class security team. In the long run, the latter is always a better bet. A great team can fix a mediocre product, but a great product can't fix a broken culture.
So if you're a founder trying to raise money, here's my advice: don't just tell me about your product. Tell me about your people. Tell me how you're building a company that can withstand the inevitable attacks that will come your way. Show me that you understand that security is not a feature; it's a foundation.
Frequently Asked Questions
How has this view evolved over time?
My thinking on most topics has changed significantly over the years. Early in my career, I held many conventional views that experience proved wrong. I try to update my beliefs when the evidence changes.
Do all experts agree with this view?
No, and that's fine. The best ideas in business are often contrarian. I share my perspective based on my experience and data, but I encourage you to seek out opposing viewpoints and form your own conclusions.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.