Ahmed Achchak (Qevlar AI) & Réza Malekzadeh (Partech): When AI attacks, can AI defend?

17 Jul 2026 · 44 min · 19 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

How AI is changing cybersecurity by making attacks easier to scale and by enabling defenders to investigate and remediate faster; argues for “assume breach” and for AI-assisted SOCs that reduce false negatives.

Guests

  • Ahmed Achchak (Kevlar AI): Machine learning engineer background; co-founded Kevlar in 2023 with Hamza Sayer. Builds an AI that investigates/responds to security incidents for large European enterprises.
  • Réza Malekzadeh (Partech): Long-time security investor; previously worked at Cisco’s security technology group on Network Admission Control. Co-led a $30M funding round for Kevlar (March).

Key claims

  • Static playbooks and manual SOC triage can’t keep up with evolving attacker paths; dynamic, agentic-style AI can mimic human investigation steps.
  • False negative rate is the critical metric; Kevlar is designed to be conservative and explain its reasoning.
  • Remediation should be automated with guardrails (human approval for high-risk actions).

Notable examples

Phishing remains effective and is amplified by generative AI; Kevlar targets phishing signals and uses its own SOC (“Kevlar”) internally. Mentions Vade/Hornet Security/Proofpoint as a European go-to-market case.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

The Evolving Nature of Security

0:45 to 2:55

Discussion on the changing landscape of security and the necessity of integrating it from the outset.

“go, the later you try to address it, the more stuff you will have to fix.”

Meet the Founders of Kevlar

2:55 to 4:18

Ahmed and Reza introduce themselves and share insights about their AI-driven security company, Kevlar.

“First and foremost, Ahmed, did I get some of this correct when I described your founding story and what you're doing?”

The Shift in Security Dynamics

4:18 to 6:19

Reza discusses the dramatic shifts in security due to technological advancements like AI.

“Maybe you can talk a bit about your own background in this context, and then we can dive into the bigger conversation about the AI shift that's happening in security right now.”

Opportunities for Small Businesses

6:19 to 8:30

Ahmed emphasizes the increased risk to small businesses and the importance of security.

“And so that was the first major shift where that traditional approach to security could no longer work.”

Innovative Approaches to Security

8:30 to 11:34

Discussion on how Kevlar is redefining security operations with AI, contrasting static playbooks with dynamic responses.

“because enterprises have already been under attacks, heavy attacks for quite some time, precisely because of what Reza said.”

AI on Both Sides of Security

11:34 to 14:00

Exploration of how Kevlar's AI counters AI-driven attacks in cybersecurity.

“I want to ask you about this because of course, underdogs is something that we in the industry tend to really like underdogs that come from another industry and try and disrupt an established one.”

AI Defense: Understanding Kavla's Approach

14:00 to 18:08

Learn how Kavla uses AI to defend against AI attackers by enhancing security operations.

“And that included some of the largest organizations on earth.”

The Fortress Model of Security: A Shift in Mindset

18:08 to 20:30

Explore the evolving mindset in cybersecurity where breaches are accepted as possible and rapid detection is crucial.

“And so that's really what we're heading for.”

Governance of AI Risk in Security

20:30 to 24:13

Understand the balance of risk governance between AI tools and client responsibility in cybersecurity.

“because we only work with enterprise accounts, right?”

Building Trust with Large Enterprises

24:13 to 28:00

Discover the strategies a startup uses to gain trust and onboard major corporate clients in cybersecurity.

“And so obviously it's up to the CISO, it's up to the security team there to decide what risk structure they want to go with.”
Show all 19 chapters

Building Trust with Customers

28:00 to 29:05

Learn how startups can gain credibility and trust with larger clients.

“And they were like, guys, we became customers.”

The Importance of Go-To-Market Strategy

29:05 to 30:24

Understand the critical role of aggressive go-to-market strategies for startups.

“And it's a lot about, you know, saying what you're going to do and doing what you said you were going to do.”

European Cybersecurity Landscape

30:24 to 31:42

Explore the strengths of Europe in cybersecurity and engineering talent.

“And you have to be super aggressive because fundamentally, execution is the most important thing.”

Case Study: Vade's Successful Journey

31:42 to 32:52

Analyze the merger of Vade and Horton Security and its implications.

“And we're seeing it with more and more cyber companies out of Europe.”

European Advantages in Security

32:52 to 34:14

Discuss the advantages European companies have in defensive security.

“And I think that completely turned the tables.”

The Role of AI in Security Operations

34:14 to 36:47

Learn how AI can enhance the functionality of Security Operation Centers.

“I do believe that this is something that we have in the product from day one, because we're probably a bit more conscious about AI and about data and what goes into what and how do you control this, etc.”

Advice for Founders on Security

36:47 to 41:17

Get key insights on how founders should approach security in their startups.

“And I kind of gave an early answer to it a few minutes ago.”

Integrating Security from Day One

41:17 to 42:00

Understand the importance of embedding security into products from the start.

Embedding Security in Product Design

42:00 to 43:10

Learn why security should be an integral part of product development from the start.

“And security basically should be embedded by design in organizations, should be embedded by designs in products.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Andreas Munk Holm:Before we get into today's episode, take a look at your screen right now, because there is something amazing in which you're having right now. If you're an impact investor or working in corporate venture, specifically in sustainability or climate, I want to flag something for you. Happening just before the famous Morroland Festival on July 23rd in Belgium, we're curating the investor program for Love Tomorrow. And there's a separate program at the Impact Circle's Investor Lounge on Friday the 24th. It's curated, it's intimate. Conversations between impact fund managers, climate LPs, and corporate venture leads.

0:30Andreas Munk Holm:We are hosting the program. If that sounds like a room that you want to be in, I suggest you go to the show notes. Security can no longer be an afterthought. In the past, people would go build something and then say, oh, let me think about the security piece. I think right now, it's one of those components that you have to take into account from the get go, the later you try to address it, the more stuff you will have to fix. Security is now a concern to everyone. Because up until now, if you were building a startup that is not from the security space, you would typically not worry about security before probably a few years.

1:06You would worry about scaling the business, etc. But now, because the bar is actually so low from an economic perspective, it's fairly easy to attack virtually any organization that you want. But the issue is attackers never follow the exact same path again. And so that meant that you had to constantly update the playbooks or accept very little automation results, like meaningful results coming out of them. And our first idea was if we switch this logic of having a static playbook to having a dynamic AI that is able to run actions by itself. What matters the most is probably the false negative rate, because that's really the one that harms you.

1:43That means that something has happened but has gone completely undetected until it's maybe too late. And I think if you have the attitude of thinking that you're absolutely impenetrable, then you're going to suffer.

1:56Andreas Munk Holm:AI has made it trivially easy to be a bad actor. You don't need to know anything about security anymore. You don't even need to write your own malware. You don't even need to know how to pop fish. The tools are there and they scale infinitely. The question every CISO or CTO, every founder running infrastructure is asking right now is, what do you do on the other side? Ahmed Ashak and Hamsa Sayer asked that question in 2023. As machine learning engineers, not as security people. They built Kevlar, an AI that investigates and responds to security incidents for some of the largest enterprises in Europe.

2:34Andreas Munk Holm:Reza Malik-Sadeh from Partec co-led the$30 million round in March. Today's conversation is the one we set up in the prep call, how AI is changing the threat landscape and what to do about it.

2:49This show is not investment advice, and the hosts of this episode may be invested in the funds and companies featured.

2:55Andreas Munk Holm:Welcome, guys. Thank you for having us. Pleasure to be with you. Thank you. First and foremost, Ahmed, did I get some of this correct when I described your founding story and what you're doing? Yeah, you definitely have. You put it in a much shorter way than I usually do. But that's exactly it. I mean, when we created Kevlar with Hamza back in 2023, we just noticed that AI was already everywhere in security, but it was mostly used on the detection side, embedded within malware detectors like intravirus, what we call EDRs, etc. And we thought that the weak link was precisely the operational side, because you now have a lot of detection tools.

3:38You have a lot of alerts that are raised as a consequence to this. But you have a bit of an issue with the capability of security operations to deal with that. You have many signals and you just are not able to investigate all of them. And we thought that we could have a role in this. And then you're absolutely right. AI is now being widely used on the attacker side. We've all read, sometimes maybe read a bit too much about Mythos and about GPT 5.5, etc. But this is just a world we are about to start living in, one where AI has a great role both in offensive and defensive security. And yeah, we were glad to be part of that.

4:17Andreas Munk Holm:And Reza, I didn't give much background on you, but you're quite the security buff. Maybe you can talk a bit about your own background in this context, and then we can dive into the bigger conversation about the AI shift that's happening in security right now. Sure. Thank you, Andreas. Well, before turning on the dark side and becoming an investor, I actually spent some time working for a variety of tech companies, and particularly at Cisco in the security technology group. where back then I worked on an initiative called Network Admission Control, which was a new way for Cisco to kind of look at devices as they were accessing the network.

4:57We were already going through some changes in the industry, and there was a lot of innovation happening in the security field, and I was lucky enough to be part of that at Cisco.

5:07Andreas Munk Holm:Yeah, and Raza, you've spent, as you just said, 20 years in this space. You've watched the cloud rewrite how the category was shaped once. Now you're seeing AI do the same thing. Some say that this is a second opportunity for massive disruption for those that are doing harmful things. But there's also, of course, an opportunity for people like Ackman. Can you talk a bit about this shift, which you saw back then, and then what you're seeing now? I think security is a super exciting space because it all keeps changing very, very dramatically each time we have another technology shift. So many years ago, people used to have all of their applications on their own servers in their basement.

5:47And it was quite easy to protect at that point. You would put a big Cisco firewall in front of your network, and you were able to filter pretty much everything coming in your network, and everything was running locally. And then the cloud came, and you started putting your applications elsewhere on other people's infrastructure. And then you actually started using components or libraries or pieces of technology from third parties to build your own app. And then you relied on other people to provide services and applications to you. And so that was the first major shift where that traditional approach to security could no longer work.

6:25You could no longer put a big piece of protection in your basement and be all done with it. today we're seeing a second major shift where AI is just dramatically changing the way people can approach technology and you know good guys like bad guys and typically the bad guys are always on the lookout for disruption because they can start and come hurt you in a way that you had not predicted in the past and so AI is helping bad guys automate attacks find new threats find new holes in your environment. And so it's just making it much, much easier for the bad guys to try and hurt you. And if on the defense side, you're not using it, then you're going to be at a disadvantage.

7:11So I think it's a great opportunity for people like Ahmed and his team to come and deliver something disruptive and something truly useful for the market out there.

7:23Andreas Munk Holm:Let me ask you one really quick question before we go over to Ahmed. Is this an opportunity or threat for only the enterprise level? Or is it something that even us smaller business owners need to start thinking about? I think it's an opportunity for everyone to think about, because even a small business owner is going to be attacked today. One of the things that AI makes easy is attack everyone, or as many people as you want. And then it's a math game of, you know, the law of great numbers. If I attack a gazillion people and I can actually, you know, hurt a few, I'm going to make what I want as an attacker.

8:03So why would I limit myself? You know, it used to be complicated to attack because you had to use tools by hand. So you would only go after the big fish. But today you can go after everyone. I mean, even my kids get so many phishing emails every day. is just scary. I actually cannot agree more with Reza. If anything, I think the increase of risk is probably higher on the small and medium businesses than it is on the enterprise accounts, because enterprises have already been under attacks, heavy attacks for quite some time, precisely because of what Reza said. These are the large fishers, the large whales that everyone has been trying to harm.

8:40But now you have a technology that makes it economically much easier to do harm at scale. And so obviously, I think that the increase of risk, as I said, is probably stronger on the S &P side.

8:52Andreas Munk Holm:Ahmed, I want to pull on a thread here because you came from ML, not security. So machine learning and AI was very much close to your heart, but then we saw this shift happen. I'd love to ask you, what did you see that the security industry hadn't seen because of your AI background? That's a good question. I think that I don't know whether it's the AI background that helped us on that specific answer that I'm about to give but I think that not coming from security just helped us dare to do things differently I'll explain what I mean by this if you look at 2023, that's the year where Kevlar got started, at the time the term AI SOC didn't even exist, like no one knew what that was, and the way security operation centers used to deal with attacks with incidents was either through completely manual operations, like humans looking at that, running investigations by themselves, pivoting from a tool to another until they have enough data to conclude that something is happening or that this is a case we can dismiss.

9:56Or they had what we call playbooks in tools called source that are responsible precisely for automation. But the issue with these playbooks is that at least back then, they were completely static, which means that you had to build a bunch of if-then-else rules nested together. And then you had a robot that would basically do whatever you told it to. But the issue is attackers never follow the exact same path again. And so that meant that you had to constantly update the playbooks or accept very little automation results, like meaningful results coming out of them. And when we started, we thought that that just sounded too old-fashioned.

10:34You said something, Andres, earlier, which is trying to balance the field a little bit between attackers and defenders, and it just seemed that attackers were favored a lot by this way of doing things, and we thought that we could dramatically change it. And our first idea was, okay, what if we switch this logic of having a static playbook to having a dynamic AI that is able to run actions by itself? And again, at the time, this word agentic wasn't even a thing yet. We needed a few marketers to work on it, to create it. But we had this idea of an AI that is able to sequentially draw actions that mimic human behavior and that makes it much faster, much more scalable to deal with incidents.

11:19And so coming back to your original question, I think that not coming from security gave us maybe the trust, maybe beginner's mistakes, if you want, but sometimes these mistakes turn out to be good ideas. And that's really what gave us the idea for Kevlar. Yeah.

11:35Andreas Munk Holm:Right. I want to ask you about this because of course, underdogs is something that we in the industry tend to really like underdogs that come from another industry and try and disrupt an established one. It of course, is what we've seen multiple times happen. We've seen it with Mark Zuckerberg, with Facebook that ended up completely disrupting media. Media was completely oblivious to that. And we've seen it as well with Airbnb, where the hotel chain said this is never going to happen, but then it did. And we've seen it again and again. Can you share a bit about how you as a VC think when you see a team that's coming from outside of an established industry and saying, we can disrupt it, whether you like it, whether you don't like it, what it makes you think and hesitate or double down on?

12:20look I actually think it's it's it's pretty uh pretty interesting because when you've been used to doing something then your ability to go out of it is actually limited time and again there are all these examples of why you're doing it like this well because we've always done it like this and I think that if you come from a different environment and of course you're super smart like these guys are and you're super hard working then you can actually think of it and do it a different way. You know, historically, we had another example in a completely different industry of Alain, who is a healthcare provider in France.

12:54And the two founders came from a different, totally different environment. And they thought, hey, let's go disrupt this thing. And they started by building a mobile app. And of course, all the traditional healthcare providers in France laughed at them, but they don't anymore because of, you know, the fact that their new approach brought such an ease of use that they're now killing it and really winning massive markets. And I think that's the interesting thing is if you come from somewhere else, you're going to think about things differently. You're going to be able to not be stuck in the same thought processes that others have been.

13:32And you can then, if you're really good, bring something innovative enough and something disruptive enough that it becomes super interesting. In a way, it's easier to think out of the box when you don't have a box at all to start from. So that's basically what summarizes the state we were in back then. So you just learn from first principles. We learned from speaking with SOC analysts. We literally reached out to people on LinkedIn and we spoke with whoever wanted to speak to us. And that included some of the largest organizations on earth. We were ourselves surprised with this. But it also gave us the trust that whatever we were building was interesting to these folks and that it was worth our times, worth a bit of sleepless nights.

14:18So, yeah, that's, I think, the advantage that we had back then.

14:23Andreas Munk Holm:Aghman, I want to ask you because you described Kavla as essentially putting an AI on the defensive side to fight the AI on the offensive side. I'd love to just walk through what that really looks like, not at the product level, but at the threat level. So we have on the one side an AI attacker that's doing what they need to do to get into a machine. But what does Kavla do in response? That's a good question. I mean, again, when you think about AI on the attacker side, you should think about it as running multiple, trying to create multiple holes in your organization, right? Like whoever the organization, you have attackers that want to get in for multiple reasons.

15:01And so you have different doors that you can use. You have the email security one. Reza mentioned phishing. that's a classic one, it's still very effective. And if anything, generative AI is making it easier to build very effective, scalable phishing campaigns. But you also have the classic malware route, you have the network, et cetera, et cetera. So basically what happens is you have security operation centers, which are basically teams of people that are responsible for triaging these signals. Because you basically have tons of signals, but you have no idea on which one are really malicious, which ones are not.

15:40And so what AI on the offensive side does is that it makes it, A, easier to do this. B, it means that you really have to react extremely fast. So even the time to react is something that a lot of organizations now want to bring down. That's where AI on the defensive side comes to play because it allows you to deal with all the signals. It allows you to do that much faster than relying on humans. humans still play a key role in our product in the sense that they are the ones that know the context about the organizations they are the ones that knows for example that i don't know something true for bank of america is less true for bnp paribas still these are two similar organizations in a sense the same industry but completely different realities completely different histories so you still need humans and humans are do bring a lot of value to the table but thanks to our product they're not dealing with incidents anymore they're dealing with facts we come to them saying we know that this is not a thesis.

16:36This is a real attack. And here is the pattern that we have seen up to you now. Do you want me to run remediation? Do you want me here's the suggested remediation that Kevlar would have run up to you? Do you want me to do it? Do you want to do it by yourself? Do you want to reconfirm everything? Here is the audit trail of the investigation. So here are all the steps that we have run, all the tools that we have connected to all the raw data, plus the interpretation from Kevlar that led us to believe that this is a malicious case. And so it's a complete game changer in the sense that you're not doing it by yourself the heavy load is taken away by the ai and it comes back to you with the results of the investigation and a good thing we are noticing more and more is our customers now entrust the product so much that they're asking for if not autonomous at least automated remediation as part of that meaning that they know that our accuracy level whenever kevlar says something is malicious or is not are probably higher than their own SOC.

17:32So now they really start to entrust us with decision making beyond the investigation side. And so that's where it gets really interesting because now we can close the loop much faster. Again, think that AI on the offensive side, if you were to reduce it to one major impact, that's the need for a much faster reaction. And so now what we are noticing is customers trust us on the investigation side. And so they're asking for, as I said, automated response to make sure that in a couple of minutes, three minutes, four minutes, not only is the investigation done, not only is the culprit detected, but also we have taken remediation actions, we have changed something in the system to harden it and make it even better for the next time.

18:12And so that's really what we're heading for. We do not want ourselves to be triage agents. We want ourselves to contribute to making the security posture of the organizations we help protect, making it much better and that's the idea of a self-healing security posture if you want. We get breached or at least we get an attack, we automatically adjust something and the AI can definitely help on this.

18:35Andreas Munk Holm:And to those that thought they heard a baby just before, you did. We have a security breach on Ahmed's side but that's being taken care of in the background. Now I want to ask both of you because what you're describing is a bit that the whole fortress model of security is that you have to accept that you cannot keep attackers out anymore. You have to assume that there is a breach or it's going to happen no matter what. What you now need to do is detect it and react as fast as possible. I want to ask both of you, is this already industry standard belief or is that something that you're still working with clients and other people you raise on your side with other founders to understand and see that this is where security is moving?

19:17I don't think it's universally accepted yet because you always have this issue of, oh, not to me, you know, others maybe. But the reality is that it's true. Like you really have to assume that nothing can be absolutely perfect. You can lock all the doors, they can get in through the window or the ventilation system or some other place. And I think if you have the attitude of thinking that you're absolutely impenetrable, then you're going to suffer. But if you do accept the fact that it's not a matter of if, it's a matter of when, then you're going to put in place the right things knowing that at some point, you know, someone's going to click on that phishing email.

19:56At some point, something's going to go through that other, you know, defense system. And therefore, you can have prepared for minimal, basically, cost to you by being prepared for detecting it, reacting to it, having trained people in advance. So I think that should be the ideal mindset for people. And the more attacks are actually put in the press, the more people are starting to take note of that and understanding that that's the new reality. But it's not perfectly universal yet. We have a slight bias here because we only work with enterprise accounts, right? Like, or large MSSPs. And when I speak with CISOs there, they clearly have understood it to be the case like the vast majority of them now know that again as you said andres this fortress model does not work anymore does not stand and that you should basically assume breach and if anything the new waves of ai publications on the security side and by this i mean clearly claude mythos and gpt 5.5 that's more on the vulnerability side of things but if anything it's showing that even on the vulnerability side you just cannot catch up You have millions.

21:08If you're an organization like, I don't know, a car manufacturer or a bank, you probably have millions of vulnerabilities everywhere. So you just need to know, you need to assume that these are all tools that an attacker can use. So the question becomes, okay, I cannot patch all of them. What do I do now? And that's where this role of AI being a sentinel, someone who constantly controls your shores, making sure that as soon as someone gets in, we're able to take them out. That's a model that probably summarizes better what the future of security would look like.

21:40Andreas Munk Holm:One thing with AI is, of course, that once you allow it to make decisions and become agentic, you're also assuming a bit of risk there. And I'd love to ask, how do you govern that risk and how much is yours versus the client's? Is it you who's the responsible party or is it the CISO who bought the product? That's a complex one. The way we deal with it is, first of all, we obviously try to increase as much as possible the accuracy rate of the tool, right? Like making sure that whenever it says something is not harmful, is benign, we'd better be absolutely certain about that. I'm citing this example in particular because everyone talks about false positives in security.

22:22but actually what matters the most is probably the false negative rate because that's really the one that harms you. That means that something has happened but has gone completely undetected until it's maybe too late. And so clearly we have a bias towards making our AI as conservative as possible meaning that it never says this is not dangerous unless it has checked every single possible case unless it has checked every possible tool it has at its disposal. It even knows when to raise its hand and to say, here, I don't think anything is happening, but because I didn't have access to the logs from system A and system B that I think would have been helpful for me, I will not conclude.

23:02Up to you to review it, up to you to add context, etc. And so the reason is, we really want to take this false negative rate as close to zero as possible, because that's the one that destroys trust with our customers. So essentially what I'm saying here is, the way we have designed the product, and we have a lot of graph AI, for example, that goes into it, It's not just an LLM that runs everything. We have designed it in a way to make sure that the false negative rate in particular is as close to zero as visible. But actually, we go beyond this. Basically, when it comes to remediation, giving the customer the ability to choose if they want to go with our remediation or not.

Read the full transcript

23:37So for now, we're just suggesting it. They're not obliged to follow it. And the reason I mentioned automated rather than autonomous remediation, there is a slight nuance, which is that the agent is not able to run remediation by themselves. You can put guardrails. You can say, for example, if it's a matter of resetting the password of a user on Sunday at 3 a.m., you can do it because the consequences of these actions are relatively limited. The opposite, if it is like reimagining a payment server, well, leave that to us. Just raise your hand. Let us know on Slack or Teams or whatever that something maybe is happening and then do not run any remediation.

24:13So what I'm trying to say is certain remediation actions have carried a much higher business operational risk for the organization than others. And so obviously it's up to the CISO, it's up to the security team there to decide what risk structure they want to go with. But essentially the tool we are building is one that gives you the control. You have the investigation capabilities that are native to Kevlar, but then you can bring remediation capabilities on our own platform on top of that. and you can use guardrails around them to say these are allowed or these are not. They need to wait for human validation, for example, or something like that.

24:46That's how we try to bridge it. And what I've said for remediation is actually true for another aspect of what we call closing the loop. And that's actually dealing with tuning the security systems of our customers. What I mean by that is detection is a matter of correlation rules most of the time. Like you have rules that say if behavior A and behavior B happen together, then raise an alarm because maybe something is happening. But more and more so, because of the data that we generate on the investigation side, we can tweak these rules. And so same thing applies here. We are not changing the rules by ourselves.

25:19We are making suggestions to customers by saying, hey guys, here there is a pattern. If we change this rule, we could have detected, for example, the attack a bit sooner and we could have had more time to react to it. We suggest that you do it. And they remain in control. they still get to decide about what happens. So essentially, to summarize all of that, we try not to be a black box. We try to drive confidence up by explaining every step that goes into the thinking of Kevlar, but we do not force any action unless customers agree to it, basically.

25:49Andreas Munk Holm:I'd love to ask both of you a bit about the commercial side, the go-to-market side of this type of business, because it's obviously very important that you don't get stuff wrong. and your partners, your clients are major corporates across the world, how do you as a three-year-old startup manage to bring on board these massive clients in such an important space as security? And Reza, maybe you can afterwards talk a bit about the broader reflections on how you as a young startup enter into a market where it's notoriously difficult to get trust built with these large enterprises? It definitely is.

26:32But surprisingly, if you do it the right way, it's almost easy. I'll explain what I mean by this. You have a lot of fluffy promises in this space. From my perspective, at least, it does hurt the space as a whole because you have a lot of folks that will come at you saying, hey, my AI is perfect. It can do everything. I'm a six-month-old startup, but still, I can do everything. By the way, same applies for incumbents. like incumbents go for same strategies sometimes they just heard about ai so all of a sudden they all have perfect ai agents that are able to do everything we have gone with a with a different strategy which is to come to customers to come to prospects rather and to say hey folks we are good at that we're very bad at this but we want to bridge it and we want to improve we want to get better do you want to see the product that we have right now so by design we had much more of a an engineer mindset trying to crack a problem rather than a go-to-market approach and it turned out that that was rather efficient and so for example when we would talk to a CISO our first reaction would be hey do not trust anything we're saying you will get to test it by yourself because again trust is not something that you win by sewing slides trust is something that you win by demonstrating it by demonstrating that your product does what you said that beyond the product the team behaves the way that you said i'll give you an example part of our team was yesterday in Germany with one of our customers there, one of the largest electronics resellers in Europe, if not the largest.

27:57One of the things that came out was they were actually comparing us to much larger vendors in the space. And they were like, guys, we became customers. Still, we still get the same care from you guys. And again, that sounds irrelevant to most of the folks. It's not to us, because to us, this is one other aspect of trust. Trust is baked into the product, but it's also baked into the teams building it and that's really the strategy that we have gone with so it's fairly simple it's just a true honest one of saying hey guys test it this is something we do well this is something that's part of our roadmap do you want to be part of that and surprisingly obviously sometimes you have people that come at you saying hey no i will go with microsoft whenever they have that in five years but you have others that feel that they have an urgent need for it right now and that they want to trust a small team at least give them their chance and that's all we've been asking about just test it have a look at it if you like it we're more than happy to collaborate together obviously if you don't well for us that that helped us already because we get we gather feedback through that experience and that that has been our go-to-market philosophy if you want

29:05Andreas Munk Holm:raja does this align with how you're thinking about how you've seen young starters build credibility with larger customers yes absolutely it's a journey right so it's not uh once you have found the magical thing that everything happens. It's absolutely a journey. And it's a lot about, you know, saying what you're going to do and doing what you said you were going to do. And I think that's super important. And this is a space where it's moving so fast and the threat and the cost are so high that you cannot afford to just sit and wait. And so I think that progressive companies are going to work with startups.

29:46And if a startup can come and prove that they're good at what they're doing and make it easy for the product to be tested, then there's no reason for them not to trust them. There are markets where people are more or less progressive, more or less inclined to working with startups. And one of the nice things with this team is that they've gone international very quickly. and so they're not just sitting and waiting for the market around them to come to them. But it's very general, right? The best startups have been super aggressive about go-to-market. I think the saying of build it and they will come doesn't really exist in this world.

30:23Absolutely not. And you have to be super aggressive because fundamentally, execution is the most important thing.

30:32Andreas Munk Holm:Now I want to go to the European philosophy or your thesis on Europe. because you've made security investments in Israel, Italy, and now France as well. You have a very specific thesis on why European cyber will be successful and how we're positioned in this current moment. Can you talk a bit about that and lay out that thesis, and then we can dive deeper together? I think, you know, cyber relies a lot on very deep engineering talent, and I think we have amazing talent. We have a very good education system throughout Europe. We have great engineers, people who can really think through complex problems and build great solutions.

31:11And even if you look at some of the larger tech companies in the world, they have massive R &D centers in Paris or elsewhere across Europe. And I think that this new generation of entrepreneurs has completely understood the importance of go-to-market on top of it. Like they're not just building, you know, in a research lab and they are building a product for the real world, right? No one buys technology. People buy a product. They buy an answer to a pain point. And that's exactly what these guys are doing. And so I think this new, very go-to-market focused, I would say, brain movement or brain position or attitude of this new generation of entrepreneurs make it such that this great technology can be very successful in the market.

31:57And we're seeing it with more and more cyber companies out of Europe.

32:02Andreas Munk Holm:You mentioned last time we spoke the Vade story and how Vade merged with Horton Security, which was acquired by Proofpoint for$1.6 billion. Can you maybe dive into that case study a little bit about what changed in the company between the founding and the exit? And the story, of course, has for Europe, as you said, for a long time been that we have great tech, but we don't have great go-to-market. But that's changing now, or rather it has changed now. Sure. So look, VEDIS, that was a French cybersecurity company, developed a great product around anti-phishing, started selling it and went and sold it internationally from the beginning.

32:41Actually, the VP of sales was not based in France. She was based in Israel, was very international mindset, and they were able to have a great presence in other markets. They realized that they could be very complementary to a German company called Hornet Security, and they decided to merge so that the entity would be much greater with a much greater market presence and more reach out in the market. And it made them a huge player at once. And I think that completely turned the tables. And so this ability to think about growing the business inorganically, it was also a great way for them to get to a size where, well, Proofpoint acquired them and it was a great, great successful exit for all those involved.

33:29And the company continues to operate. They're a huge business unit as part of Proofpoint. And so I think that's a very nice testament to the go-to-market success in Europe.

33:41Andreas Munk Holm:Ahmed, could you comment on what we just heard from Reza here? Is there a real European advantage when it comes to defensive security specifically? Like some would say data sovereignty, GDPR, the way large enterprises think about infrastructure here. Do you think that this all makes sense and converges to become a real advantage for us? I think it does to a certain extent. I'll give you an example. Having started out of Europe, GDPR is a thing. And so, for example, I've mentioned throughout the conversation how easy it is to control what the AI is doing. I do believe that this is something that we have in the product from day one, because we're probably a bit more conscious about AI and about data and what goes into what and how do you control this, etc.

34:25So I'm not talking about GDPR on the law side, on the legal side. I'm talking about the consequences that it means for engineers, because you basically hear about these kind of things all the time. So that means that whenever you think about a product, you have a bit more chances of thinking about making it transparent, explaining what data, making sure that the customer remains in control. For example, when you go to Kevlar, you have the integration center, and within the integration center, you can literally say, I allow Kevlar to use that piece of my data set. I allow it to connect to my sim and within the sim only query these tables.

35:03And again, this is something that we have baked into the product from day one, I think because of this data consciousness that is probably higher in Europe than it is anywhere else across the globe. So I think that, yes, this gives a slight advantage to people thinking about security product for Europe from Europe. I think obviously there are geopolitical tensions right now. It's not a surprise to anyone. And that probably helps a little bit European companies in Europe. That's not for example the card that we play. We don't play the sovereign card in our case. We do believe that if anything Europe deserves to have champions that can sit at the tables of the big tech companies.

35:41And to achieve that, if these companies from a go-to-market perspective only focus on Europe and sell a European product first, my fear is the market is not big enough. And so I'm not saying that the European market is small. What I'm saying is to really have champions, you need to have companies that are able to play global plays. And we have good examples of that. We have a lot of successful companies in Europe recently on the AI space in particular, thinking about Legora, thinking about Lovable, etc., that are clearly going for a global play. And that's something that we're trying to copy as well.

36:16So we do have very happy customers in the US. We do invest a lot on our go-to market in the United States, and we will continue to do so. We are thinking about Asia now because it's becoming interesting for us. And precisely, we do not want to just serve Europe with a purely European mindset. We have to think global because the pain is global. And again, the market is there, so the winners will be the ones that just dare to reimagine the space, dare to be hangrier maybe than others, and dare to just move fast, and we're trying to do that as much as we can.

36:47Andreas Munk Holm:So if we stay on that thread for a bit, you're three years old, you're 30 million in, with some of the most demanding enterprise logos on your books, what has to be true for the next three years for Kavla to be the obvious answer to the AI landscape problem? That's a question I ask myself a lot. And I kind of gave an early answer to it a few minutes ago. and that's moving out of the investigation side. Like really our thesis is SOC security operation centers should not be reduced to a triage function. We think that's a design mistake almost. I'm not blaming SOC analysts by any means. I'm not saying that.

37:30What I'm saying is they don't have the right tooling and what we have asked from SOCs is precisely to behave as a triage unit. And I think it's a mistake because ultimately when you think about a SOC, these are the teams that are able to see what is missing in a server configuration because they know that the server has been under attack under heavy attack they know that each time we receive the phishing case this set of employees have clicked more easily than others so maybe we should train them first but the issue is all we're asking for them is hey you need to triage fast and to tell us whether it's malicious or not and then you move on to something else so they very much have a firefighter mentality, which is good because it helps extinguish fires.

38:10But we do believe that there are many insights that the SOC can actually can derive for the rest of the organization. And so that's really what we're trying to bring to the table. An AI that not only is able to investigate, remediate, etc., but also is able to heal your organization over time, to detect what went missing, what went wrong, and to correct it over time. And I do think that if we're able to make that switch and we're actively working on that, if we're able to make that switch, then clearly our impact will be much bigger than just making the suck faster. It will actually help balance the field, as we said, between attackers and defenders.

38:45And really all we are dreaming about is making the attacker's life a little bit harder because it's been probably too easy for now.

38:53Andreas Munk Holm:Reza, in your IC meeting, I'm sure you underwrote this three-year scenario, five-year, ten-year scenario as well. What did it look like? What is it that underpins your underwriting of this 30 million round? The team. I think for me at this stage, the most important thing is the team and how they've executed to date and how I believe they'll be able to continue executing. I mean, I'm not a big fan of massive projection spreadsheets because ultimately you can put whatever you want in them and I don't tend to believe them. But I think that this team has shown that they can execute and they've shown their hunger for building a true product, a true approach to the market and a true company.

39:41And that's what we're excited about. You know, they've never promised the moon and the stars, but they've been executing step by step. And I think they're the right folks to go and make the most of this market.

39:55Andreas Munk Holm:Beautiful. Now, let me ask both of you, if someone's listening to this episode that's not a CISO, but a CTO or a founder, and they know that they probably still have a security problem they haven't yet dealt with, what's the one thing that you think they need to understand about the current moment and what AI will do to the market? They just need to run and call Ahmed. That's the only thing they need to do. I mean, by the way, I'm more than happy to help if I can. like talking to other founders that are about to start their journey. By the way, I don't know whether that's exactly what you meant with the question, but if there are any founders that are about to start their journey, please do reach out.

40:37I mean, obviously, it's always great to speak with other founders. One of the important aspects is motivation and energy over the long run. It's not easy. That's my big piece of advice, if I can give one. It's not easy, but it's so damn exciting. So obviously, the more you can speak about it, the more you can learn from other founders going through similar things, the easier it gets. And also for Europe, it means that we will be able to build a large cohort of dreamers. Some of us will be able to make impact. Like ultimately, it's a numbers game, as Riza said earlier. But then if we're talking more through the lens of pure security, obviously, we'd be more than happy to help.

41:16the first thing that anyone really needs to understand is that security is now a concern to everyone because up until now if you are if you were building a startup that is not from the security space you would typically not worry about security before probably a few years you would worry about scaling the business etc etc but now because the bar is actually so low from an economic perspective like it's fairly easy to attack virtually any organization that you want we are ourselves for example targets of phishing and phishing attacks like a lot of phishing cases uh by the way we use our own product against that uh like we we have our own sock which is literally kevlar uh dealing with our own alerts because we have an edr internally we have all the tooling that is needed so my point is my main message to them is security may not be your first concern from day one because obviously it will be running your business making sure that you get these early customers etc etc but at least try to bake it into the product so that when it becomes a real thing, you won't have stupid, silly mistakes to undo, and you have something straight, straight, straightforward from day one.

42:25And security basically should be embedded by design in organizations, should be embedded by designs in products. Because again, some of these startups will turn out, I hope, to be unicorns, to be the next champions. The sooner they think about security, the best it will be for them. Yeah, I think if I can add to that, security can no longer be an afterthought. I think a lot of times in the past, people would go build something and then say, oh, let me think about the security piece. I think right now it's one of those components that you have to take into account from the get-go because the later you try to address it, the more stuff you will have to fix.

43:04And so I think it's in your interest and benefit to think about it upfront.

43:10Andreas Munk Holm:Thank you, Ahmed. Thank you, Rasa, for coming on the podcast to talk about this very important topic. I think it's very, very clear. We're all talking about the mythos moment and everything over the past couple of weeks. And I have a feeling that it's not something that's going to go away. Rasa, thank you so much for coming on the podcast. Thank you. It was a pleasure. Thanks for having us.

From the publisher

AI is giving attackers cheaper, faster ways to target organisations at scale. On the defensive side, security teams are starting to replace rigid playbooks with AI systems that can investigate incidents, adapt to new attack paths and support faster response.

In this episode, Andreas Munk Holm speaks with Ahmed Achchak, Co-founder and CEO of Qevlar AI, and Réza Malekzadeh, General Partner at Partech, an investor in Qevlar AI.

They discuss how Ahmed and his co-founder approached cybersecurity without coming from traditional security backgrounds, why that outsider perspective helped them rethink static playbooks and how Qevlar AI is moving security teams beyond manual triage.

The conversation also covers why organisations should assume breach, how automated remediation can be governed without turning the system into a black box, how young startups earn trust with major enterprise customers, Europe’s cybersecurity opportunity and why founders need to build security into their products from day one.

Highlights

  • How AI is reshaping cyberattacks and cyber defence
  • Why static security playbooks are falling behind
  • How an outsider perspective shaped Qevlar AI
  • How Qevlar AI investigates and responds to incidents
  • Why organisations should assume breach
  • How startups build trust with enterprise customers
  • Europe’s opportunity to build global cybersecurity leaders
  • Why security must be built in from day one

---

Learn more about the Love Tomorrow Summit and the programmes EUVC is curating, and secure your tickets here.---

Timestamps

  • (02:00) Introduction to Qevlar AI and Partech
  • (03:00) How AI is changing cybersecurity
  • (05:00) From cloud security to the AI shift
  • (07:20) Why small businesses are increasingly exposed
  • (09:00) Building Qevlar AI without a traditional security background
  • (12:00) Why outsider founders can rethink established industries
  • (14:20) How Qevlar AI investigates cyber incidents
  • (18:30) Why organisations should assume breach
  • (21:30) Governing AI-driven security decisions
  • (26:00) Winning trust with enterprise customers
  • (30:30) Europe’s cybersecurity advantage
  • (34:00) Why European companies still need to think globally
  • (37:00) Qevlar AI’s long-term vision
  • (39:00) Why Partech backed the team
  • (40:30) Why security can no longer be an afterthought
  • (43:00) Closing thoughts

More from EUVC

All 626 episodes
Ahmed Achchak (Qevlar AI) & Réza Malekzadeh (Partech): When AI attacks, can AI defend?EUVC · 44 min
Listen in VO