E548 | Carlos Moreira da Silva, 33N: How Europe Can Lead in Cyber and AI Security

15 Aug 2025 · 31 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

EUVC Podcast Episode Notes

Episode Title

E548 | Carlos Moreira da Silva, 33N: How Europe Can Lead in Cyber and AI Security

Episode Overview In this episode of EUVC, co-hosts Andreas Munk Holm and David Cruz e Silva converse with Carlos Moreira da Silva, a co-founder of 33N, a venture capital fund focused on cybersecurity. The discussion revolves around Europe's role in leading cybersecurity and AI security, the funding gaps in the European market, and the necessity for a unified cyber strategy in the face of rapidly evolving threats.

Key Themes and Topics Covered

  1. The European Cybersecurity Market
  2. Size and Fragmentation:
  3. Europe's cybersecurity market is substantial but fragmented, impeding early-stage startup growth.
  4. The European investment in cybersecurity is significantly less compared to Israel and the US.
  5. Investment Gap:
  6. Discussion on the annual funding gap of €1-2 billion for cybersecurity startups in Europe, revealing a crucial area for development.
  1. The Role of ECSO
  2. European Cybersecurity Organization (ECSO):
  3. ECSO aims to unify the fragmented cybersecurity ecosystem in Europe by fostering connections between startups and investors.
  4. The organization has been pivotal in raising awareness and mobilizing investment in cybersecurity.
  1. Global Competition and Technology Stack
  2. Tech Stack Control:
  3. Europe risks falling behind as the tech stack is predominantly controlled by non-European countries.
  4. Cybersecurity as a Defense Strategy:
  5. Emphasizes the importance of cybersecurity in national defense, advocating for Europe to build its own leaders in the tech ecosystem.
  1. Investment Strategies and Challenges
  2. Need for Specialized Cybersecurity VCs:
  3. Importance of having venture capitalists who specialize in cybersecurity to effectively support startups, referencing successful models in Israel and the US.
  4. Market Dynamics:
  5. The necessity for an investment platform that allows European funds to focus on cybersecurity, facilitating growth and competition.
  1. Cybercrime vs Cyber Spending
  2. Market Analysis:
  3. The disparity between the $10 trillion cybercrime market and the $200 billion cybersecurity spending market highlights urgent funding and strategic challenges.
  1. AI in Cybersecurity
  2. Dual-Use of AI:
  3. Discussion on how AI can be employed by both attackers and defenders, necessitating new strategies for protection, compliance, and governance.
  4. Emerging Market Opportunities:
  5. As AI technology advances, the importance of integrating it into cybersecurity strategies to mitigate risks and enhance defenses is emphasized.
  1. Building Global Champions
  2. Championing European Startups:
  3. Advocates for creating global leaders not just within Europe but on an international stage, emphasizing the importance of nurturing a robust investor ecosystem.
  1. Networking and Community Engagement
  2. Invest for Cyber Networking Night:
  3. A call to action for investors to engage with European cybersecurity funds during events like Superventure, aiming to build momentum in the community.

Key Takeaways

  • Fragmentation is a Barrier: Europe's fragmented cybersecurity landscape poses a significant hurdle to startup growth, necessitating a cohesive approach.
  • Investment Gap Needs Attention: Immediate action is required to address the substantial investment gaps in the European cybersecurity sector.
  • Specialization Matters: Specialized venture capitalists are crucial for the success of cybersecurity startups, aligning with trends seen in other successful markets.
  • AI's Dual Role: AI presents both challenges and opportunities in cybersecurity, underscoring the need for robust defensive strategies.

Conclusion Carlos Moreira da Silva provides valuable insights into the state of cybersecurity in Europe, emphasizing the necessity for unity, investment, and strategic growth. The episode compels listeners to reconsider Europe's potential in the cybersecurity landscape and highlights actionable steps for stakeholders to take in fostering a strong, competitive ecosystem.

---

For full details or to listen to the episode, visit [EUVC](https://eu.vc).

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Europe's cybersecurity market is massive, Yet the very structure of this market is stopping its own companies from winning. The European market is one of the biggest markets in cybersecurity in the world. It's a challenge for European startups to grow on it at a very early stage because it's very fragmented. While the rest of the world pours resources into cyber innovation, Europe is left with a dangerous funding gap. Israel alone was investing almost the double of what the EU was investing in cybersecurity. This isn't just about software. It's about control over the very technology stack that powers the modern economy.

0:36The tech stack is controlled pretty much by non-European countries. We should be concerned. Meanwhile, criminals are operating at a scale we've never seen before. And they're better funded than the defenders. The cybercrime market is worth$10 trillion. And now, AI has entered the fight, turning attacks way faster, smarter, and much harder to stop. Attackers are using AI as well. So they are always looking for ways to scale. This is Carlos Moreira da Silva on the urgent race to turn Europe's weakness into its greatest advantage. Listen to the full conversation on the EUVC podcast.

1:15We're hosting an exclusive off-the-record LPAMA's, bringing together the people behind the capital who are shaping the next generation of venture funds. If you're in the middle of raising a fund, or planning to, and want to understand how LPs actually make decisions, this is the room you want to be in. No pitch decks, no posturing, no script, just honest conversations between GPs and LPs. The upcoming AMA on the 21st of August is held by Jonathan Sibelia, partner at Bullhound Capital, and one of Europe's most experienced LPs. Before Bullhound, he led fund-to-funds and secondaries at Molten Ventures for 16 years, deploying into 80-plus VC funds and backing breakout names like UiPath, Revolut, and Ledger.

2:00Jonathan brings a rare dual lens of direct investments and secondaries across thousands of fund reviews and real DPI outcomes. This is your chance to ask one of Europe's sharpest LPs how they really assess managers, secondaries, exit strategies, and what most GPs still get wrong, or anything else you're dying to know. Access to these AMAs are limited to EUVC community members. Don't miss your chance to be in the room. Head to eu.vc forward slash subscribe to save your seat.

2:48This show is not investment advice, and the hosts of this episode may be invested in the funds and companies featured. Welcome back, everyone, to this week on the UBC podcast. And we're diving into Europe's cybersecurity moment with Carlos Moreira de Silva. I have tried as best as I can to learn Portuguese pronunciation. I'm not really nailing it yet, but I hope everyone was at least somewhat pleased with that. Carlos, you're the co-founder of 33N, a conviction-led fund backing the next generation of cybersecurity and infrastructure founders in Europe. And you're bringing to this a rare edge because you're blending deep B2B operator experience on the one side with, of course, the sharp investor insight on the other.

3:30We will explore today the underfunded and misunderstood state of cybersecurity in Europe. what a great cybersecurity investor should look for in startups and how their fragmentation might just be Europe's biggest assets, especially if we learn how to navigate. So, Carlos, you're also part of the, I do believe, founding committee behind the EXO organization, the European Cybersecurity Organization. And maybe we could start right there to begin with. Tell me about EXO and why EXO is important at this time. Look, first of all, thanks for having us at this podcast. It's a pleasure to be here and to explain about the challenges that the European cybersecurity ecosystem is going through and what we are doing to foster the ecosystem all across Europe.

4:20And EXO is relevant exactly on that context, right? EXO is the association of most of the entities across Europe in cybersecurity, and that's been pushing for a stronger and more dynamic sector in Europe. EXO started back in 2015, 16, and at that time, I believe probably the name cybersecurity didn't even exist, right? So it was InfoSec and things like that. or it was very close to that if we remember the situation back then there was not even a forum for cyber security startups to meet investors in Europe there were forums like this in the US RSA was already quite established in UK there were also some quite strong events but in EU it was very scattered it was really tough for an European cybersecurity startup to meet with investors.

5:27And that's why there was this group, the investors working group created within Exo, from which I must share exactly to foster that ecosystem, to bring together all startups, to create a critical mass so that investors could be interested in attending those events, to create more interactions between both sides. A few years fast forward, so we started also analyzing which were the challenges, the other challenges of the ecosystem. And one of them was really relevant, right? The gap of investment between Europe, Israel, and the US. So basically, Israel alone was investing almost the double of what EU was investing in cybersecurity.

6:17And regarding how do we compare it with the U.S., so Europe was more or less 30 % of the global market and the U.S. around 40%. And then on the investment side, the gap was really huge, almost one-tenth. So we started trying to launch some initiatives to further reinforce the investment ecosystem in Europe. after that there was this launch of an advisory study by the european investment bank reaching to to the conclusion that there was a an annual gap in europe of one to two billion in um in in cyber security startups so this is a bit the base to set the context as it is today there are several initiatives to try to close this gap, but I believe it's a good starting point for our conversation.

7:13And that was a bit the nerdy insider perspective on the state of the ecosystem. If we then try and zoom out and look at the cybersecurity threat that we are experiencing in Europe, one could frame it as saying that there's an intensification and absolute sophistication of cybersecurity threats that are reshaping the geopolitical investment landscape. That's a big headline. Could you unpack that a bit and tell me what are we seeing that's making it all the more important that Europe gets more focused around cybersecurity? First, it's not just about cyber, right? When the tech stack is controlled pretty much by non-European countries, we should be concerned on being able for our companies to be competitive in what regards access to new technology, to emerging technology that can help them get to that position of being competitive.

8:18If added to this, European companies are also, or maybe also in a disadvantage of having access to that stack in a secure way, then the concern is even bigger, right? And the tech stack has been evolving a lot. So first the cloud, now the AI stack, and Europe is becoming behind. And so it's even more relevant for us to have our autonomy on the security side. Right? It's not only relevant, it's even mandatory when this also becomes a relevant part of the European defense. So one of the areas of defense is for sure cybersecurity. And of course, we need to play. It's not about protectionism. That I like to underline.

9:17It's being able to play on a level playing field and able to build our own worldwide segment leaders. That's what is at stake. Where are you seeing within cybersecurity the biggest factor, so to say, for startup origination to happen? Europe, I believe we have a significant motivation to create emerging startups. We have excellent universities. We have excellent tech knowledge. If a few years before what we were seeing coming from Europe were basically companies that already, so similar to the ones that had already emerged on other regions like Israel and the US. Now, it's not that case any longer.

10:17What we are seeing right now are startups in Europe that are appearing at the same time on very emerging spaces than in other regions. So the challenge right now is not so much having the early stage startups on interesting segments. is how to support them to be able to create those global category leaders, right? Because if startups are not playing at the same, on the same conditions or backed by the same conditions as the international peers are, then they will be left behind. There has been a lot of investment on the very, very early stage in Europe, in several countries. What is now a challenge is that exactly that fragmentation.

11:05We have seen several countries in Europe putting a lot of cash on very early stage, but we need to have a more holistic approach to it, right? Not just country by country, but at the full European level. What do you see being done? Where do you position yourself? What's the work that EXO does to help mobilize this? That's what I've touched at the beginning right so first we had to raise the conscience that the european market is one of the biggest markets in cyber security in the world and so we are a market that is quite attractive for companies from outside to come and essential if a company from abroad wants to become a global category leader it needs to come to europe so europe is a very interesting market now it's a challenge for European startups to grow on it at a very early stage because it's very fragmented.

12:07So that's why we need to end that fragmentation, right? And just by bringing startups from all Europe corners together, do events all across Europe, bringing those startups investors, there has been made a lot of progress because right now, Europe in cybersecurity early stage has really this platform for exposing innovation to investors. Regarding the challenge of scaling these startups, what we realize is that the best ones attract them to change to other geographies. when in Europe we don't have the funds with the size, with the specialization to be able to duly support those companies to scale in a competitive way with their international counterparts.

13:00And so that's why EXO has been pushing for the creation of a European investment platform that could enable European funds focus or specialize in cybersecurity and thus able to really support those companies to scale to have larger funds and to be able to compete with their international peers. Is it a requirement that the funds are specialists in cybersecurity or does cybersecurity lend itself perfectly well for generalist investors? Cybersecurity is a very complex ecosystem. We believe it's really key for investors to be specialized, even because when we look at other geographies, that path has already been done.

13:52When you look to Israel or to US, so geographies where there is enough critical mass, investors have already became specialized or have specialized funds exactly to be able to support these companies in the best way. And so if in Europe we don't have specialized funds, we will not be able to support these companies in the same conditions. That's our profound belief. That can be explained with access to talent, the support on getting these companies the best positioning, advising them on the best way on the go-to-market, and so on. Can you expand a bit on the funding initiative that you described just before?

14:39I don't know to what extent it's public. Not so much public at the moment, right? We know that there's a lot of backing by public institutions, by several countries around Europe. And so eventually we'll know something more in the next month. But it's good to see that the community has already realized that something needs to be done and that there is a lot of support for something to happen. Yeah. Can you tell me a bit about, because it is quite significant that there's getting to be actual real support from the major institutions. Could you tell me a bit about some of the learnings from this process of building momentum around EXO and the cybersecurity movement?

15:29what have been pivotal. One thing is obviously Ukraine happening and everything kind of following thereafter. But I imagine that there are also steps you've taken that could be learned from by others. You mean by other segments? Yeah, by other organizations that are trying to move forward their agenda within something else than cybersecurity. I believe there are even other regions in the world looking to do the same that we have been doing here in Europe, right? There are other regions for whom cybersecurity is a very relevant topic. Don't have just alone, country by country, the critical mass to do anything.

16:13And they need to come together, join forces to be able to push for the development of the ecosystem. One of the things that was fundamental is to understand what was the marketing need at the moment, right? So startups not being able to find investors, investors having to go to every European country to try to find startups. And so the matchmaking events was really fundamental. And then EXO has done an excellent job in creating the space for listening, the needs from investors, from startups, in which were the next challenges. And it was not a quick process, don't get me wrong, but being persistent on developing those discussions, on evolving more and more public institutions, I think it was really key, right?

17:11To the extent that then EIB also shown interest in approaching the subject in a very structured way, that was really fundamental. And then, of course, raising the attention also country by country, right? So getting to the process, several countries across Europe so that we could build momentum around our project. I'd love to ask you also about AI specifically, because before we spoke about how everything is moving in the industry and the increasing importance. But I imagine that AI, to a large extent, has also rewritten a lot of the rules. So on one side, attackers are using AI as well. And so they are always looking for ways to scale their attacks in sophistication.

18:03but also in terms of their addressable market. On the defense side, on the protection side, we also need to use it in our favor. If there will be a larger volume of attacks and our security teams are already overwhelmed, we need to understand how to use AI to automate our protection. Right? That's fundamental. How to write call in a secure way with the support of AI, for instance. how to help us better protect from fraud that is becoming more and more realistic because attackers are using AI, right? So there's a lot of fronts where AI is changing the way we do security and is actually mandatory for doing security right now.

18:54And I'm not talking about having the nice looking AI-based chat, right? That's nice as well. But there's much more to it, right? The other aspect is technology adoption by corporations across our vision. One of the critical aspects that companies look at for implementing AI is securing their data, securing their knowledge, being compliant. Otherwise, it can pose a very serious threat to those organizations. reputation for starting with, right? So, addressing. I just heard of a major pension fund that had rolled out AI across the company and now they have people being able to ask the AI what is the CEO's number of meetings or based on the CEO's calendar, how many work hours and stuff like that.

19:57Not very fortunate. There are several cases like that. And organizations are also learning, right? So organizations are learning on how to implement AI. Security for AI is being built, so it's not everything built right now. So everything that needs to do with compliance, with governance, with assessing the security of that stack, but also maintaining it secure when it is being used, right? So a lot is happening right now. And we need to look at it as an opportunity for investors because there's an emergent market appearing. But we also need to be careful because a company that is not using AI right now may be disrupted by another one that will appear in the short term with AI capabilities.

20:46A common saying in anything related to defense or crime is that you will, by definition, always be behind the perpetrators. And I imagine that with AI, that is even more true than it has been before. Let's see. Cybercrime is a hell of cyberspending. Yeah. So the cybercrime market is worth$10 trillion. The cyber spending market is 200 billion. Yeah. Right. So they probably have more money to keep developing their technologies. For now. Tell me, Carlos, what are you doing investing in cybersecurity? You should be investing in cyber. I don't think that is a good investment strategy, though. No, no, no, no.

21:42Or at least it's hard to reach for. Not sustainable or ethical. But there's a lot to be protected. And for sure, Europe needs to play at its scale, at its position, really needs to push for its ecosystem. It's not just about creating large organizations. That's, I believe, a very important message. Champions are not the champions of their own region. They need to be the global champions in certain segments. Otherwise, they will not be champions in a sustained way. So we need to create global champions. And for that, we need healthy investors ecosystem. We cannot just lock the best companies to the European market.

22:35We need to let them grow to be invested by investors based in Europe so that those companies don't need to go abroad. Is there a natural conflict there in that venture automatically is global? Also in where the capital comes from, oftentimes we see companies starting here and moving to the US. Is there a natural problem when it comes to having that model marry with cybersecurity? I don't believe so. Look, so at 33N, we are a global investor. And we actually, we believe we are best positioned as investors to support companies growing this segment by being exposed to the most sophisticated market.

23:23Because how can we help a company in Europe to compete globally if we don't know what's happening in the US or what's happening in Israel? U.S. companies, they also appreciate to have European-based investors because they want to address this market that is relevant for them. So the other way around will also happen. So I believe that this is a positive for an European-based company to have capital from other regions. The diversity of capital adds value. The other thing is not to have alternatives in Europe to lead those investments and allow those companies to stay in Europe. Could you tell me a bit about the market of investors that are most active in cybersecurity?

24:13Who are the people that people should know? Point to a database like Defense Investors have a specific place, one run by our good friend, the former CIA guy, Eric. is there a place like that for cybersecurity where everyone can go and understand what is the ecosystem like? I think EXO has a good mapping of the European ecosystem. But again, what I believe is that startups should look for investors that really can have value besides the money. And that value differs from stage to stage. Europe needs very strong regional early-stage investors specialized in cyber. We need pan-European investors specialized in cyber.

25:07And we need to have VCs, global VCs, that can play head-to-head with their counterparts from other regions. So we need a very healthy ecosystem. And there are several options for that. But my strong advice is really for startups to look for VCs that can have more value than just the cash. Yeah, which comes back to the importance of having specialists. I'd love before we close, Carlos, just to hear about the Invest for Cyber Networking Night in Berlin. You're doing it during Superventure. I'd love to ask you two things. One, what is going to happen? Two, why is it that, and you've spoken about this already, but why is it that it's important to bring it to a place like Superventure?

25:55First of all, we believe, and we have demonstrated it, that investing in cyber, first of all, it's fun. Second, it's a good contribution for the community. And third, it's quite interesting from an investor standpoint because of the returns, right? LPs should be aware of this. Cyber is very fundamental. is a sector that has shown a very significant resiliency during these last two, three years and delivers interesting returns. And Europe needs funds with larger capacity. So why not to promote investment in European funds close to the LP base that will be at Superventures? So that's why this has been started already a few years ago and is gaining our momentum because LPs are realizing that really this is an interesting segment to look at.

26:56Just before we close, I want to ask one final question. That is, where do you see cybersecurity ending and defense starting? Or is it the same or sub-segment of defense? How should people think about that? So cybersecurity is for sure a crucial element of defense, especially nowadays, where more autonomous devices, vehicles are used. Those systems need to be protected. There's a lot related with intelligence as well. So for sure, cybersecurity is critical. The other thing is, and to your question regarding the difference between cyber and the defense side, most of the technologies used on civilian cybersecurity can be applied to defense.

27:53Probably most of the companies we invest in have dual use for defense as well. So, of course, there are technologies that are just used for defense. To those, the question is, is it a technology for defending ourselves or for attacking the other party, right? At 33N, we prefer to be focused on the defense side. So, first of all, we are not doing anything just for defense. We are investing in cybersecurity for the civilian world. And of course, with use cases on defense, but that's the line that we draw, right? Yeah. And technology that is used for defending ourselves, not for attacking. It does sound like a very tempting business model to build for attacking though, and then have a side business focused at the multi trillion dollar cyber crime space.

28:51But that's maybe someone else to pick up. Carlos, thank you so much for joining me on the podcast today. Thanks, thanks for having me. Thank you.

29:26partner at Bullhound Capital and one of Europe's most experienced LPs. Before Bullhound, he led fund-to-funds and secondaries at Molten Ventures for 16 years, deploying into 80-plus VC funds and backing breakout names like UiPath, Revolut, and Ledger. Jonathan brings a rare dual lens of direct investments and secondaries across thousands of fund reviews and real DPI outcomes. This is your chance to ask one of Europe's sharpest LPs how they really assess managers, secondaries, exit strategies, and what most GPs still get wrong, or anything else you're dying to know. Access to these AMAs are limited to EUVC community members.

30:10Don't miss your chance to be in the room. Head to eu.vc forward slash subscribe to save your seat.

30:22more than just an alliance. This is a union of values. Let's start acting.

From the publisher

Carlos Moreira da Silva brings a rare blend of insight: a deep B2B operator, a specialist investor at 33N, and a leading force behind Europe’s cybersecurity coordination efforts through ECSO. Together, we explore why cybersecurity is Europe’s opportunity to lead, not follow, in the new geopolitical tech stack.


Here’s what’s covered:

  • 01:15 What is ECSO and Why It Matters for European Cyber

  • 03:30 Mapping the Cybersecurity Investment Gap: US vs Israel vs Europe

  • 05:20 The Tech Stack Power Shift: From Cloud to AI, and Why Security Must Catch Up

  • 07:30 Europe’s Fragmentation Problem—Or Its Untapped Advantage?

  • 09:45 The Role of ECSO in Building a Unified European Cyber Strategy

  • 11:45 Why Europe Needs Specialist Cybersecurity VCs

  • 15:30 What Other Movements Can Learn from the ECSO Playbook

  • 20:00 Cybercrime vs Cyber Spending: The 10 Trillion Dollar Wake-Up Call

  • 21:30 Building Global Champions in Cyber (Not Just Regional Winners)

  • 25:00 What Startups Should Look for in a Cyber VC (Beyond the Check)

  • 26:30 Invest for Cyber @ SuperVenture: Why the LP Community Should Pay Attention

  • 28:00 Where Cyber Ends and Defense Begins—Drawing Ethical Boundaries at 33N

More from EUVC

All 626 episodes
E548 | Carlos Moreira da Silva, 33N: How Europe Can Lead in Cyber and AI SecurityEUVC · 31 min
Listen in VO