Building a security startup as an outsider

Kabir Mathur (CEO and co-founder · Lean)

BSides NYC 2025 (0x05) · Day 1 · Entrepreneur

Overview

In a candid and insightful talk at BSides NYC, Kabir Mathur, CEO and co-founder of Lean, shared the unconventional journey of building a cybersecurity startup from the ground up, despite having virtually no prior experience in the industry. Titled "Building a security startup as an outsider," Mathur's presentation challenged the traditional notions of expertise and credentials, arguing that an outsider's perspective and raw curiosity can be a significant advantage in an often insular and jargon-heavy field. Lean's mission is to create a unified API for security data, aiming to normalize disparate data from various security solutions into common schemas, making it easier for security teams and other vendors to correlate and action critical information.

Watch on YouTube

Visual summary for Building a security startup as an outsider by Kabir Mathur
Visual summary for Building a security startup as an outsider by Kabir Mathur

Key moments

  1. 0:00 Introduction: Starting a security startup as an outsider
  2. 2:00 What Lean does: Unified API for security data
  3. 3:40 The difficult decision to pivot after 146 rejections
  4. 5:00 Building a company in a non-traditional way as outsiders
  5. 6:50 The key insight for Lean: Security tools' core problem
  6. 8:00 Validating the idea with 50 practitioners despite skepticism

Building a security startup as an outsider

Speakers: Kabir Mathur, CEO and co-founder, Lean

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=nwuroxB1ooQ

Overview

In a candid and insightful talk at BSides NYC, Kabir Mathur, CEO and co-founder of Lean, shared the unconventional journey of building a cybersecurity startup from the ground up, despite having virtually no prior experience in the industry. Titled "Building a security startup as an outsider," Mathur's presentation challenged the traditional notions of expertise and credentials, arguing that an outsider's perspective and raw curiosity can be a significant advantage in an often insular and jargon-heavy field. Lean's mission is to create a unified API for security data, aiming to normalize disparate data from various security solutions into common schemas, making it easier for security teams and other vendors to correlate and action critical information.

Mathur's narrative is a testament to the power of iterative learning, radical transparency, and a relentless focus on solving real-world problems. The talk resonated deeply with founders and security professionals alike, offering a fresh perspective on innovation, market validation, and team building within the cybersecurity landscape. It underscores the idea that while technical proficiency is crucial, understanding the human problems and communicating solutions clearly can unlock new avenues for progress and trust in an industry often driven by fear and complexity.

Background

▶ Watch: Introduction: Starting a security startup as an outsider (0:00)

Kabir Mathur's journey into cybersecurity was, by his own admission, an accidental one. With a background spanning gaming, adtech, and martech, and roles in business development, customer success, and product partnerships, Mathur had "zero background in security." This lack of traditional security expertise became the central theme of his talk, framing Lean's inception as a "stumbling into" the industry rather than a deliberate, expert-driven venture.

Prior to Lean, Mathur and his co-founders were developing an AI co-pilot for the customer success space, a venture they abandoned after 146 investor rejections. This initial failure, though painful, provided crucial lessons in market validation and the necessity of finding a "must-have" problem rather than a "nice-to-have" solution. The pivot that led to Lean was catalyzed by their third co-founder, Neil, who possessed direct security expertise from his time at BlueVoyant, a large Managed Detection and Response (MDR) provider. Neil's experience building BlueVoyant's internal data automation and orchestration platform exposed a critical pain point: the immense frustration of dealing with a multitude of disparate security APIs, the arduous task of normalizing data, and the challenges of managing complex data pipelines.

Neil's key insight was profound: security tools are often built for buyers (like CISOs) and non-technical personas, focusing on flashy demos and high-level promises, rather than for the engineers and developers who actually have to manage, integrate, and maintain these tools day-to-day. This leads to a pervasive problem where "more tools equals more overhead," data becomes trapped in silos, and security engineers are relegated to the role of "data janitors." Critical issues, as a result, often slip through the cracks. This problem, while not immediately intuitive to Mathur and his other co-founder Akash given their non-security backgrounds, resonated as a "gnarly, boring problem" worth solving – precisely the kind of challenge they were drawn to.

Key Findings

▶ Watch: The difficult decision to pivot after 146 rejections (3:40)

Lean's journey and Mathur's insights highlight several key findings about building a security startup and the industry itself:

  1. The "Outsider's Advantage": Mathur emphasized that not knowing everything was their "biggest advantage." Their lack of preconceived notions allowed them to approach problems with fresh eyes, ask "dumb questions" that insiders often overlook, and prioritize clarity over industry jargon. This "weaponized ignorance" enabled them to identify fundamental pain points that established players might have become desensitized to.
  2. Curiosity Scales Better Than Credentials: Despite lacking traditional security credentials, Mathur and his team prioritized learning. They conducted 91 interviews with practitioners in under three weeks, cold-messaging 250 strangers on LinkedIn. This intense focus on understanding the problem space, coupled with a willingness to learn in public (through podcasts, newsletters, Reddit threads, and industry reports), built trust and authority more effectively than any pre-existing network or expertise could have.
  3. Security is Sold, Not Bought: Mathur observed that, much like gym memberships, security is not something people are inherently excited to acquire. Vendors must actively prove its importance and value, rather than expecting organic demand. This implies a need for clear communication and demonstrable problem-solving.
  4. Tools are Built for Buyers, Not Users: A critical observation was that vendors primarily target CISOs and other high-level buyers, leading to products optimized for sales demos rather than the daily grind of security engineers. This results in painful user experiences and contributes to the "data janitor" problem, where engineers spend excessive time on integration and data normalization.
  5. The Communication Problem: The security industry is rife with jargon, endless Gartner categories, and vendor-created acronyms. Mathur noted that marketing often focuses on fear rather than clarity, making it difficult to discern the actual problems being solved. Lean consciously decided to use plain English, comparing themselves to familiar concepts like Zapier, Plaid, or Segment for security, making their value proposition intuitive even to non-security professionals.
  6. Strategic Go-to-Market for Startups: Instead of immediately pursuing long enterprise sales cycles, Lean initially targeted other security vendors. This strategy allowed for quicker iteration cycles, compressed decision timelines (weeks instead of 12-18 months), and faster revenue generation. This enabled them to build a robust product and business more rapidly, playing to their strengths as a startup serving other startups and scale-ups.

Technical Deep Dive

▶ Watch: Building a company in a non-traditional way as outsiders (5:00)

Lean's core technical contribution centers around addressing the pervasive challenge of security data fragmentation and interoperability. The company is building a unified API for security data, designed to abstract away the complexities of integrating with a myriad of security solutions. This involves three primary technical components:

  1. Integrations: Lean develops and maintains connections with major security solutions across the ecosystem. This includes a wide array of tools that generate logs, events, alerts, and stateful security data. The goal is to provide a comprehensive network of data sources.
  2. Data Normalization: A critical problem in cybersecurity is the lack of standardized data formats. Each vendor typically has its own proprietary API and data schema. Lean tackles this by normalizing the incoming data from these diverse sources into common data schemas. This process is essential for making data from different tools comparable and usable for correlation and analysis.
  3. Unified API: The normalized data is then exposed to customers via a single, coherent unified API. This API serves as a central gateway, allowing security teams and other vendors to access, query, and action data from multiple sources without needing to build and maintain individual integrations or parse disparate data formats.

Mathur highlighted the limitations of existing standardization efforts, specifically mentioning OCSF (Open Cybersecurity Schema Framework). While OCSF is a community-backed standard for certain types of security data, particularly logs and events for Security Information and Event Management (SIEM) systems, it doesn't adequately cover stateful security data. This includes contextual information about assets, vulnerabilities, configurations, and other dynamic security states that are crucial for comprehensive analysis. Lean aims to fill this gap, aspiring to standardize a significant portion (80-90%) of security data, even acknowledging that 100% standardization might be unattainable due to vendor-specific nuances.

The underlying problem Lean addresses is the "data janitor" role that security engineers are often forced into. Instead of focusing on proactive defense or threat hunting, engineers spend an inordinate amount of time writing custom scripts, managing data pipelines, and manually normalizing data to get a holistic view of their security posture. By providing a normalized, unified data layer, Lean intends to free up security engineers from these menial tasks, allowing them to focus on higher-value activities like threat detection, incident response, and security automation. The technical foundation is built on enabling seamless data flow and intelligent correlation, effectively turning a fragmented data landscape into a cohesive, actionable resource.

Demo / Proof of Concept

▶ Watch: The key insight for Lean: Security tools' core problem (6:50)

This talk was primarily focused on the entrepreneurial journey, strategic decisions, and philosophical approach to building a security startup as an outsider, rather than a technical demonstration of Lean's product. As such, no live demo or specific proof of concept of Lean's unified API or data normalization capabilities was presented during the session. The speaker focused on the why and how of their company's formation and market validation.

Defensive Implications

▶ Watch: Validating the idea with 50 practitioners despite skepticism (8:00)

While the talk didn't present new vulnerabilities or attack techniques, its insights carry significant implications for security leaders and practitioners (defenders) in how they evaluate, adopt, and even contribute to the evolution of security tools.

  1. Demand User-Centric Tools: Defenders should actively seek out and advocate for security products built with the security engineer in mind, not just the CISO. Prioritize tools with clear, well-documented APIs, intuitive data schemas, and ease of integration. Challenge vendors to demonstrate how their solutions reduce the "data janitor" burden rather than adding to it.
  2. Prioritize Clarity Over Jargon: Security leaders should be wary of vendors who rely heavily on buzzwords, Gartner categories, and fear-based marketing. Instead, demand clear, plain-English explanations of the problem being solved, the mechanism of the solution, and its tangible benefits. This encourages vendors to articulate real value rather than obscure it with complexity.
  3. Embrace Transparency from Vendors: Lean's approach of "radical transparency" – sharing architecture diagrams, making API documentation public, and building in public – fostered trust. Defenders should look for similar transparency from their vendors, as it indicates confidence in their technology and a willingness to collaborate.
  4. Advocate for Data Standardization: The talk highlighted the critical need for better data standardization beyond existing efforts like OCSF. Defenders can drive this change by demanding that their chosen tools support common data formats or by actively participating in initiatives that promote interoperability. This will reduce vendor lock-in and improve the effectiveness of cross-tool correlation.
  5. Foster an Open-Minded Approach to Innovation: Security leaders should be open to collaborating with and adopting solutions from non-traditional vendors or "outsiders" to the industry. Mathur's story demonstrates that fresh perspectives can lead to innovative solutions that address long-standing, "boring" problems that insiders might overlook. Gatekeeping can stifle innovation; inviting curiosity can unlock it.
  6. Internalize the "Learn Faster Than You Sell" Philosophy: For internal security teams building their own tools or automations, the principle of rapid learning and validation is crucial. Talk to internal users, understand their pain points deeply, and iterate quickly before committing significant resources.

Ultimately, Mathur's talk empowers defenders to be more discerning buyers and more effective advocates for the tools and practices that genuinely improve their security posture and operational efficiency.

Key Takeaways

  • Weaponize Ignorance: An outsider's fresh perspective can reveal critical problems and innovative solutions that industry veterans might overlook. Don't fear what you don't know; use it as an advantage.
  • Prioritize People Over Products: Before writing a single line of code, deeply understand the problems of at least 50 target users. This foundational understanding is crucial for building solutions that truly resonate.
  • Learn Faster Than You Sell: In a complex industry like security, continuous learning and adapting to feedback are paramount. Building trust by genuinely understanding the problem is more effective than aggressive outbound sales.
  • Embrace Radical Transparency: Sharing architecture, API documentation, and building in public can foster trust, credibility, and a supportive community, even in a security-conscious environment.
  • Communicate with Clarity: Avoid industry jargon and acronyms. Describe solutions in plain English, using analogies to familiar concepts (e.g., "Zapier for security") to make complex ideas accessible.
  • Curiosity Scales Better Than Credentials: In the long run, a relentless pursuit of understanding and a willingness to ask questions will open more doors and drive more meaningful innovation than relying solely on established expertise.

About the Speaker(s)

Kabir Mathur is the CEO and co-founder of Lean. He describes himself as an "outsider" to the cybersecurity industry, having had no prior experience in the field until two years before giving this talk. Mathur moved to the US in 2005 from Mumbai, India, for college and has since spent his career in various startups. His background includes working in gaming, two adtech startups, and most recently at Typeform in the Martech space. Across these ventures, he has held diverse roles leading business development teams, customer success, product, and partnerships. His experience building Lean reflects his philosophy that curiosity and an outsider's perspective can be powerful assets in even the most technical and skeptical industries.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent founder story about building a security data integration startup with no prior industry background. Lean's unified API angle is a real problem worth solving, but this talk lives entirely in the entrepreneurial-journey lane — there's nothing here that a BSides audience couldn't get from a decent Medium post or a 20-minute podcast episode.

Heather Calloway (CISO) — WEAK

A sincere founder story about a legitimate operational problem — security data fragmentation is real, and the 'built for buyers, not users' critique lands — but this is a startup pitch narrative dressed as conference content. It doesn't change how any security leader operates, governs, or decides.

→ Top-rated talks at BSides NYC 2025 (0x05)

All talks from BSides NYC 2025 (0x05)