In short
EUVC Podcast Episode Notes: E309 | Startups in Focus by Seedcamp
Episode Overview
- Title: E309 | Startups in Focus by Seedcamp
- Guests: Carlos Espinal (Managing Partner, Seedcamp) and Johannes Keienburg (Co-founder and CEO, Cakewalk)
- Focus: The evolution and future of access control management, challenges in data security, and insights on effective access management processes.
Key Themes
- Access Control Importance: Discussion on the critical role of access control in organizational security and visibility.
- Data Security Challenges: Analysis of the increasing complexity of data security, especially with the rise of AI and decentralized software usage.
- Future of Access Control Management: Exploration of how access control processes will evolve as organizations grow and incorporate more technology.
Episode Structure Introduction
- Launch of Seedcamp’s new series "Startups in Focus"
- Carlos Espinal introduces Johannes Keienburg, sharing the podcast's objective of discussing company-building experiences.
Guest Background
- Johannes Keienburg: Shared his journey from digital health to founding Cakewalk, highlighting the challenges he faced with data visibility and management.
Discussion Points
- Visibility as a Security Challenge:
- Importance of knowing what data and access points exist within a company.
- The direct correlation between visibility and security risk management.
- Data Security Challenges:
- Insights from a security engineer on N26 regarding visibility as a primary challenge.
- The need for organizations to understand their application landscape and access points.
- Role of Cakewalk:
- Cakewalk’s approach to access management focuses on instant visibility and easy implementation.
- Solutions designed for smaller companies that lack the resources for complex IAM systems.
- Future of Access Management:
- Shift from role-based access to behavior-based access control.
- The potential for Cakewalk to influence how organizations build and secure software.
- Founders’ Advice:
- Early-stage companies should prioritize security and access control from day one.
- Implement practical processes and educate employees on the relevance of these measures.
Key Takeaways
- Implement Early: Companies should establish access control practices early to avoid chaos later on.
- Visibility is Crucial: Understanding the full landscape of applications and user access is essential for security.
- Future-Proofing: As technology advances, access management processes need to adapt to maintain security integrity.
- Holistic View on Security: Good security practices not only protect data but can also enhance business opportunities.
Conclusion
- The episode emphasizes the significance of evolving access control management processes in response to technological advancements and security threats. It calls for proactive measures in organizations to ensure they are not just reactive to security issues but are building a solid foundation from the beginning.
Further Connections
- For engagement with Cakewalk and insights from Johannes, links will be provided in the show notes.
- Listeners are encouraged to follow the Seedcamp podcast series for more discussions in the startup ecosystem.
Closing
- Thanks to Carlos Espinal and Johannes Keienburg for sharing their insights on access control management and the evolving landscape of data security.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00Welcome back, everyone, to another episode of the European VCBZ Podcast. Today, I have a very different episode for you because today we are not launching a normal EUVC episode, but instead we're launching one of the Seatcamp podcast episodes because they have just launched a new series called Startups in Focus. And that is with our good friend, Carlos Espinal, the managing partner and one of the two founders of Seatcamp, who is interviewing and talking to portfolio founders and friends in the ecosystem about building companies. And that is something we have not done too much of on the European VC podcast.
0:37So for that reason, we thought this was a perfect match for our platform. So I really hope you'll enjoy this episode. I know I did. It is between Carla Haspinala, as said, with Johannes Keinberg, the CEO and co-founder of Cakewalk. The episode dives into a topic that I know absolutely nothing about, which says exactly why this is not the type of Fenty view that I am doing on the European DC podcast, because I am what I would probably refer to as a fund nerd and not as much a startup nerd. Maybe the latter will come as I grow an experience, but let's see. This episode dives into how Johannes has really worked with Kate Walk on building access management processes in the early days of their organization and the challenges of ensuring data security and also, of course, the evolution and future of access controls.
1:32So as you're going to hear, a topic that I know absolutely nothing about, but which Johannes, as the founder of Cape Walk, knows a ton about and Carlos, as one of the early investors, knows quite a bit about as well. So here, with no further ado, let's pass the mic to Johannes and Carlos.
1:56the gold standard should be that people request for access before they actually access something and that's actually also the best way for a company to get to a proper asset overview you're listening to this much i know the seed camp podcast
2:30Hello, everyone. On today's episode, I have one of the SeedCamp founders that I really, really enjoy spending time with and working with, partially because it's an area that I'm also partial to, which is cybersecurity, but also because he's doing some really interesting stuff in the space in light of what many people take for granted, which is how to take care of a lot of the applications that your employees use. So on that note, welcome, Johannes. Hello, Carlos. Johannes, you know, one of the things that I really enjoy about the way that you and your colleagues operate is that you guys are very much like, you know, you say something and you guys, the next week I find out that you guys are shipping.
3:13And I wanted to understand a little bit about where you came to do what you're doing now with Cakewalk. What was your background? What made you think about doing this? Is it something that you always were passionate about? Or was this something that you sort of stumbled upon through triangulation? Just tell us the story of how you got to where you are today. I mean, I've spent quite some time in digital health and in healthcare, right? And healthcare obviously deals with very sensitive patient data. So there's a lot at stake. And a couple of times, I guess the worst situation was suddenly learning about a huge database that the team created on Airtable.
3:56I love Airtable, but I didn't love that database because there was like really, really, really sensitive private patient data on that Airtable database. And no one knew about it. That's the first time when I myself understood and thought, okay, this was a risky situation. And what was really risky about it is that no one was kind of aware of the fact that this data was out there and that there was no sense of this is a difficult situation. um that's the first time that kind of i really experienced um i would say the pain because i started looking into ways how to tackle that and i never found i never found a good solution yeah there are enterprise solutions um helping you to to to manage excess of employees to software and to to data but i never found a good solution let's say for a fast-moving environment yeah and that's really very much, I would say, the moment that got me thinking.
5:04Excellent. So walk us through a little bit more on how you were thinking about how you would buy and sell a lot of what you're building because when I think about the challenges of trying to secure data, especially when you look at a company like yours, you have not only to educate a lot of people, you have to help the CEOs or whoever the companies are that are using something like Airtable to train people to think differently. And then you have them to trust you as an emerging platform. And so there's a lot of that, which requires buy-in from the internal organization, maybe some education. Walk us through a little bit about outreach, who your customer is and what it is that sort of clicks in their mind that they're like, hey, look, this is exactly what I need and this is why I'm going to engage.
5:59Yes. So let's start with the problem. I spoke to a super fascinating security engineer from N26 the other week. And I asked her the question, what's the biggest challenge that she has in her day-to-day life, keeping her company secure? She also works with quite some external clients, helping them with ISO certifications and so on. And her answer, she didn't even think for a second. She immediately went like, visibility. That's my number one challenge. Yeah. So the obvious next question is like, why is visibility such a kind of security challenge for you? And I love the sentence that she said. It's a great quote.
6:46She simply said like, well, everything that I don't know is a security challenge or a security risk or security threat. And that makes sense, right? Because what you don't know, you can't protect. and and with that sentence we're already getting very much to the essence of the problem that we are tackling with cakewalk companies have employees employees access in a kind of very decentralized manner these ways software employees integrate software into a company's processes and companies have no visibility anymore of what's going on really and that's a major security risk employee accessing applications employees uploading data to applications which is a good thing right from an efficiency perspective don't get me wrong we want everyone to use these applications but you as a company want to understand what's going on and I would say we are seeing a new dimension of that problem with the rise of fantastic AI tools that that entered the market in the last 12 months, because that's almost the next level of tools out there, even more SaaS usage, even more tool usage.
7:56And also the way these tools start to interact with your existing system landscape is a next level. And again, same problem here. You as a company don't even know that your sales team is using certain AI tools and maybe even connected that to your existing system landscape, which gets us into the problem of machine-to-machine access. And this is essentially what we are tackling for companies because we help companies to really get to instant visibility in terms of what applications and what accesses are out there, but also to establish a very easy to implement access control logic so that you actually tackle the problem at the origin, right?
8:42Visibility, trying to discover things from the top is good, but the gold standard should be that people kind of request for access before they actually access something. And that's actually also the best way for a company to get to a proper, I would say, asset overview in terms of what's really out there. That's, I would say, the problem and the product in a nutshell. You've also asked, who do we have to convince as a still young company? The typical buying persona for Cakewalk is the head of IT, the IT manager or the security manager in a company. These are the people who are operationally involved in the process.
9:26And of course, there are tons of strong arguments for many other stakeholders in the company while implementing a solution like ours doesn't make tons of sense, even in the early days. Yeah, so I think that the word that stood out for me was visibility. It sounds like a lot of the leadership in the company is lacking visibility on not only how their colleagues are using services, but how even colleagues are building and interacting and interconnecting services. And so part of what sounds like you're helping them to do is providing that visibility and then providing some structure for control on authorization and access.
10:12Now, walk us through a little bit about how that evolves. Like in your ideal organization, how does that evolve? You know, the traditional toolkit out there for identity access management and role-based access management, a lot of those already exist. for traditional apps and you would build them in. Whereas what Cakewalk is, is more of a, is a new way of looking at integrating SaaS products and SaaS products are interconnected. How do those two converge? That's a great question. Yes. I mean, yes, there is a first generation of identity and access management kind of platforms out there. Some of them are really great tools.
10:56I would say a few things have changed why they are not the perfect starting point for every company. And one major insight here is I would say that most of these companies are more built for enterprise customers. Most of these companies are pretty, they are powerful, but they are also pretty complex in terms of initial onboarding and also in terms of maintenance. They are by now managed service providers to help large enterprise customers to roll out some of these IAM platforms. And what I'm really convinced of is that there's a new generation of companies who don't have the internal resources and also not the financial means to go for such a complex process.
11:50They need something that seamlessly integrates into their landscape. They need a solution that you can literally roll out within minutes. And there are a few things attached to what it means to roll out a solution within minutes. It really all starts from one thing or from one topic that all relates to the question of how you interact and connect and integrate with the very tools that you want to discover. What you see in many of the existing solutions is that companies would have a few tools in their identity and access management solution that are pretty high level of integration or very deep level of integration.
12:41And that takes tons of time. For these few applications, you then have also powerful automations. but these few deeply integrated applications will be 10 % or maybe even just 5 % of the actual tool landscape that is out there. And that's a development that I really see in the market that there's no point in having from your identity and access management perspective, just a few deep integrations with a few tools. What you really need as a company coming back to visibility is to immediately see the entire landscape of software out there. And that's one of the core promises that we make, that you can get to that discovery within a very, very short period of time with zero integration effort as a customer.
13:31Yeah, it's very fascinating for me that, you know, for those of the listeners who are familiar with OWASP, that the OWASP top 10 are the top 10 web application security risks. And number one in 2021 is broken access control. And in many ways, it's really interesting to see that you have targeted the first one, broken access control, perhaps in secure design, which is number four. security misconfiguration, number five, and number seven, identification and authentication failures. And to some extent, what I'm curious about is how much you think that in a world where more and more users use Cakewalk, they re-architect the way that software is built because of Cakewalk.
14:20Yes, that's a great question. I wanted to come back to the facts, Carlos, first that you just mentioned. That's really important to bear in mind, right? 80 % of the security incidents or data leakages out there are related to identities.
14:41Identities, of course, there's tons of threats that you have within this broad space of identities. It can be a phishing attack, so someone gets a hold of your passwords. But what you really need to understand, and again, we're coming back to visibility now, is the broader your surface of attack is, the weaker is your overall posture, right? Your overall security posture. And that's why access controls and tight access controls are so important to enhance your overall security sort of positioning, right? And that's why, in fact, there's a super strong connection between tight access controls, least privilege, ideally, access controls, visibility, and kind of reducing your surface and attack.
15:32And coming back to the quote that I shared earlier, being able to actually understand your surface of attack before you actually start to protect it. So those numbers are really, really fascinating. To your other question, I mean, let's. I guess it's interesting to understand where normally a company stands when they when they integrate a solution like ours. Normally, what we find in companies is some in-house solution. yeah um in-house and in-house solution would probably mean there's a certain process in place that people people are supposed to at least submit an access request when they when they kind of introduce a new tool when they want to get access to a new application that can be via email this can be like in a slack channel and some poor person in the company has the has the cumbersome task to kind of get hold of all this and kind of host a spreadsheet where you kind of have some sort of asset management.
16:39Running this, as you can already imagine when we're just speaking about this, running this in a manual manner is next to impossible though, right? People won't stick to this process because that's simply not how people are wired. Yeah, write an email before you access something. Well, I might. I might also not. And nobody realizes that's the problem. There's no real consequence because people can just bypass such system. And then from the person who's supposed to host that asset list, the list is out of date the second you updated it. So that's some, some I would say indication or background why it's so cumbersome and difficult to run this show in a merely manual manner yeah but there's a lot at stake yeah and that's what companies in in my perspective increasingly understand we see a clear tendency that more and more companies early on go for ISO 2701 certifications or in the in the US market for SOC 2 certifications to enhance their infosec standards.
17:50And I guess that's my strong hypothesis. That's for two reasons. One reason is that more and more people understand that a robust security posture is of highest importance for your company. At the same time, this has become a revenue enabler, right? Especially if you're a B2B company, your customers will make this a requirement that you have super strong standards here. And that's good news, of course, for everyone who's selling security products. Yeah. I wanted to keep on pushing on this idea of what the future organization looks like though, because I think one of the interesting things that we spoke about at one point, and I don't know how near in the future this is, but it's much more dynamic in terms of roles and role definition.
18:44You know, right now, you have a more of a classical model, right? You belong to an organization, you belong to a group, you're a sort of user, or you're something else, right? And then that defines your access policy. But, you know, you build in a lot more flexibility, not only for individuals, but also for machines. And so I'm curious, what is the future of the world? What does an organization look like 10 years from now when they're using Cakewalk? What does it allow them to do that you wouldn't normally do? And I'm not talking about transitioning from manual to automatic. I'm talking about how does work fundamentally change because of your existence?
19:26I love that question. And that's something I'm incredibly passionate about. So you mentioned something very important here, and that's like group based or role based access, right? I mean, to be fair, introducing a role based access is very challenging for most companies today. And if you are able to introduce role based access, you're already kind of achieved quite something just for everyone to understand what that means. It means like you ultimately define like for every role in your company, employee in the marketing team, leader of a marketing team and so on, what the like normal standard default accesses look like that someone in this role should have.
20:10Having such sort of structure is a major milestone for your overall access control policy. And actually, it sounds very, very complex. But at the end of the day, once you sort of implemented that, it actually makes your life easier because it takes away ambiguity. It's very black and white. And normally, that's a good thing for processes. Right. So that's the first comment that I wanted to make. Implementing a group based, a role based access is a great achievement today for a company. now when I look into the the future what I see and what's what's something or what is something that I'm really really passionate about is the future is going to go beyond kind of default roles or groups it's going to be more behavioral like there are patterns that we see there are patterns that we can recognize within organizations and within these patterns you have typical sort of excesses that look healthy and there will be patterns that look non-healthy and non-normal right and that's definitely a development that is going to come and it is going to be a change for in the way companies will think about access controls and that's something that we at Haguework, fair to say, also extremely passionate about.
21:33I love this idea of patterns um very interesting uh and it sounds like what you're when you're saying patterns and maybe now we're going into like future sneaky sneaky stuff uh on your in your vision here but it sounds like patterns are both um maybe an overlapping with identities so you know who you are you know what pattern and when things might be able to to happen um if we rewind the clock a little bit back to your original customer when we were talking about them. Some of them might be, it might be too early to engage with you. Maybe not. What advice would you give to any founder starting a company right now, hiring the first two or three employees?
22:17What would be a good foundation for them to think about that would enable them to then either engage with you down the road or at least prevent a series of issues? Because not everyone comes from the same background you do. And so as a consequence, they might be focused building something entirely unrelated to what you offer and may not necessarily take the right steps early days. So what would be your top three recommendations? Yeah, also a great question. Thank you, Carlos. And actually, I posted about this today on LinkedIn. So here's the thing. The world has changed. We spoke about that. security is a threat or insecurity is a threat for every company out there.
23:01And I guess the number one mistake that companies can make and should not make is to ignore this in the early days for too long. It's always easy to say, okay, look, I need to build my business now, right? I need to find product market fit. I need to make my first hires. I might need to close a fundraising round. Yes, that's all true. The longer the wait, you wait, the more painful it will get at some stage. And this stage where you need to tackle access controls, it's going to come. That's set in stone. So you know it's going to come. And you know the longer the wait, you wait, the worse the exercise will get.
23:41So my clear number one advice is implement very practical. You can get going in a super 80-20 manner, but implement very easy, practical processes from day one. Educate your early employees that this is kind of an important part of your company culture. That's how I would put it these days. Explain to your people why this is relevant as management. Make it a top management priority. Explain to your people the why and the how. And then get going with an easy, practical process in the first place. And an easy practical process in the first place to me means there needs to be some sort of asset overview somewhere.
24:26Someone needs to be responsible for that overview in the first place. Maybe it's actually the CEO in the very early days. It can be your CTO. Educate people that everyone should use great software, but they need to kind of adhere and stick to a certain access request process. This can be a simple Slack notification in the first place that you can also review, right? And where you have a history so that you can document that there's at least a practical process in place. This is how I would go and review this once a quarter because once you've got that baseline in place, it will be way easier for you to enhance your process and take next steps versus a world where at some stage, at some stage and at some day, it's just utter chaos, right?
25:15And you need to get going with kind of backward engineering, trying to understand what has grown in your company. That's going to be a very, very painful experience. And again, you will reach that point. Any company will reach that point where some customer is going to say, hey, but I want this from you. Can you give me some proof that you're running this because this is important for us? Yeah, that's my number one advice here. Nice. Well, it was very fun to chat very quickly about what you're doing and how you're doing it. For anyone who wants to get a hold of you, what's the best way? Well, get a hold of you and then you will get me in touch.
26:04Ah, I see how it is. I'm your sales department now, huh? Nice. Well, guys, we'll share with the links, Johannes' blog post, his website, and different ways that you can get in touch and engage with Cakewalk. But yeah, it was very fun and quick to share your story and what you're building. And thank you for joining us, Johannes. Thank you so much, Carlos. This was fun as always. Next time, guys, talk soon. Bye.
From the publisher
- The importance of access control, visibility, and security in organizations.
- Insights on the need for access management processes.
- The challenges of data security.
- The evolution and future of access controls.
- … and more that you can discover on EUVC.
Chapters:
00:03 Launching Seedcamp Podcast Series: Startups in Focus
00:45 Meet the Guests: Carlos Espinal and Johannes Kainberg
01:14 Diving Deep into Access Management with Cakewalk
03:02 Johannes's Journey to Founding Cakewalk
05:05 Addressing the Challenges of Data Security
05:45 Understanding Customer Outreach and Engagement
10:33 Integrating SaaS Products for Enhanced Security
10:46 The Future of Identity and Access Management
15:57 Implementing Access Controls in Companies
18:23 Envisioning the Future Organization with Cakewalk
19:37 Role-Based Access and Its Evolution
22:09 Advice for Founders on Early Security Steps
25:49 Closing Thoughts and How to Connect




