In short
Pathfounders Podcast Episode Summary
Episode Title
Qevlar AI raises $30M to bring AI to cybersecurity
Podcast Description Pathfounders, hosted by Mike Butcher, discusses the tech startup and venture ecosystem, focusing on innovative companies and trends. This episode features Qevlar AI, a cybersecurity startup that has raised $30 million to enhance cybersecurity with AI solutions.
Key Guests
- Ahmed Achchak: Co-Founder and CEO of Qevlar AI
- Damien Henault: Partner with Forgepoint Capital
---
Episode Overview
Introduction
- The episode opens with a discussion on the overwhelming number of cybersecurity alerts faced by Security Operation Centers (SOCs) and the inefficiencies in addressing these threats.
- Mike Butcher mentions findings from Forrester and Gartner about the challenges in cybersecurity operations.
Qevlar AI's Approach to Cybersecurity
- Founding and Mission: Qevlar AI, founded in 2023, aims to leverage AI to automate responses to cybersecurity attacks by transforming previously invisible data into actionable insights.
- Technology Framework:
- Agnostic Design: The platform integrates seamlessly with various detection tools (e.g., antivirus, firewalls) and alert types (e.g., email security, endpoint alerts).
- AI-Powered Decision Making: The AI collects necessary data upon receiving an alert, analyzes it, and determines whether the threat is malicious or benign within three minutes.
- Autonomous Recommendations: The AI not only identifies threats but also provides actionable remediation steps (e.g., blocking malicious IPs, re-imaging servers).
---
Key Concepts Discussed
The Role of AI in Cybersecurity
- Efficiency Over Manual Processes: Qevlar AI reduces the reliance on human SOC analysts for triaging alerts, thereby streamlining operations.
- AI Collaboration: The technology utilizes multiple machine learning models working together, enhancing accuracy and enabling a trustworthy autonomous system.
Investment and Growth
- Qevlar AI recently raised $30 million, led by Partec and Forgepoint Capital, to expand its market presence and enhance its technology.
- Damien Henault's Insights:
- Emphasizes the uniqueness of Qevlar's AI-native approach compared to retrofitted AI solutions in cybersecurity.
- Highlights the team's technical expertise and ambition as crucial factors for investment.
Competitive Landscape
- Qevlar faces competition from other cybersecurity startups and established companies like CrowdStrike and Splunk.
- The company's unique selling points include superior accuracy and a lower false-negative rate, which are critical in maintaining trust in automated security systems.
---
Future Directions
- Qevlar AI aims to expand its capabilities beyond investigation to include full-scale threat detection and remediation, establishing itself as a comprehensive cybersecurity platform.
- Plans to target both European and US markets to position Qevlar as a global player in cybersecurity.
Conclusion
- The episode wraps up with reflections on the necessity of AI in modern cybersecurity in response to increasingly sophisticated threats.
- Ahmed Achchak and Damien Henault summarize their goals for Qevlar AI, focusing on enhancing the product, ensuring customer satisfaction, and exploring new markets.
---
Key Takeaways
- Cybersecurity Challenges: SOCs are inundated with alerts, leading to inefficiencies.
- Innovative Solutions: Qevlar AI employs a unique, AI-native approach to streamline investigations and responses.
- Market Potential: With a $30 million funding, Qevlar is poised for growth and aims to redefine cybersecurity operations.
- Trust and Performance: Maintaining low false-negative rates is vital for the adoption of autonomous cybersecurity solutions.
---
This episode of Pathfounders provides insights into the evolving landscape of cybersecurity and the significant role AI plays in enhancing operational efficiency and threat response.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOThe Challenge of Cybersecurity
0:45 to 2:48
Discussion on the overwhelming volume of cyber threats and alerts in security operations.
“And I'm joined today by Ahmed Ashek, who is CEO and co-founder of Kevlar AI.”
Kevlar AI's Approach to Cyber Attacks
2:48 to 3:52
Ahmed Ashek discusses how Kevlar AI automates responses to cyber threats.
“And I know that your company started in 2023.”
Autonomous Response in Cybersecurity
3:52 to 5:27
Exploration of how Kevlar AI autonomously manages alerts and provides remediation steps.
“So I was looking at your platform and it claims to be able to respond autonomously in about three minutes.”
Funding and Market Position
5:27 to 7:00
Discussion on Kevlar AI's recent funding round and its competitive edge in the market.
“So you're trying to say that the step change here is it's actually trying to deal with the problem as well?”
Competitive Landscape in Cybersecurity
7:00 to 8:39
Analysis of Kevlar AI's positioning against major competitors in the cybersecurity space.
“and I'm delighted to say we're also joined by Damien from ForgePoint Capital, Damien Hohner.”
Future Potential of Kevlar AI
8:39 to 14:01
Discussion on the future of Kevlar AI, including potential for growth and market exits.
“So that's why we invested first a year ago and a year after, you know, they've been delivering on all fronts.”
AI's Role in Cybersecurity Detection
14:01 to 16:49
Explore how AI enhances cybersecurity operations and threat detection.
“So I think, you know, So for us, we're really there to help them realize their true potential independently.”
Transforming SOCs with AI Capabilities
16:50 to 17:53
Learn how AI can revolutionize Security Operation Centers for better threat management.
“And then the second part of your question was, is Kevlar some sort of a Trojan horse that starts with investigation and want to move to something else?”
Investment Trends in Cybersecurity and AI
17:54 to 20:26
Understand the key investment areas shaping the cybersecurity landscape.
“So you start with one aspect of the of the problem and then you can start working on other aspects.”
Strategic Use of $30 Million Funding
20:27 to 22:26
Discover how Kevlar plans to use its recent funding to achieve its market goals.
“Now, Ahmad, you've raised this$30 million.”
Transcript
Automatic transcript. May contain errors.0:00Mike Butcher:Hello and welcome to Path Founders with me, Mike Butcher. Now, security operation centres, or SOCs, are overwhelmed by the volume of threat alerts they must manage. Of course, cyber security is top of mind for many companies today. In fact, the analysts Forrester found that just three attacks can trigger thousands of alerts for companies. And Gartner estimates that 70 % of time is spent on triage and investigation. So as you can imagine, this is an enormous space. And of course, in the world with the world today, there's just enormous amounts of cyber attacks every day. Paris-based Kevlar AI automates the response to many of these attacks.
0:47Mike Butcher:And I'm joined today by Ahmed Ashek, who is CEO and co-founder of Kevlar AI. Welcome to Path Founders. Thank you, Mike. Thanks for having me. Great to be here. So do you want to unpack a little bit about how Kevlar approaches this problem? Yeah, I mean, the first thing is, as you mentioned, Mike, we are living a day where attacks are becoming mundane. Like every company is targeted times and times again every single day. And these attacks are getting more and more integrated. Up until now, the solution has been, you know what, let's throw humans at it. Let's have SOC analysts investigate all of that.
1:27And hopefully they will be able to cover all the insights that they see. The problem is, because of the number of these attacks that is drastically increasing, because of them becoming more and more complex, we cannot do that any longer. And so the starting point of Kibla is exactly this one. How can we help organizations repel these attacks? how can we help them respond to them much faster and so the way our technology operates is that first of all it is agnostic which means that it does not care about the detection tool it can be your antivirus it can be your firewall logs it can be your sim we don't really care about that as long as you have something that goes red and that says hey something is worth some analyst's time they will essentially handle that by itself so it's built to be agnostic to the stack as i said, but it's also agnostic to the type of alerts, meaning that whether that's an email security alert or an endpoint alert or a cloud security, we don't really care either.
2:21We're able to handle that from A to Z. And so as soon as the alert comes up, the AI will connect back to the systems, to the environment of the customer, collect all the data it needs and get back to the analyst saying, this is clearly something malicious or at the opposite, this is something benign. I mean, Ahmed forgot his password and no need to worry about that. And in doing so, we drastically reduce the amount of manual work needed by analysts. We help them navigate the noise much more efficiently.
2:47Mike Butcher:Right. And I know that your company started in 2023. Was it built with AI in mind from the ground up or did you retrofit a generative AI later on? That's a good question. I mean, no, we were as AI native as the company can be. We started literally with a single AI machine learning model that we had. And then today we have nine models that all collaborate together, some of which are generative AI based. Some others are machine learning, like classical machine learning, Bayesian learning, these kind of things. But essentially, all our systems are machine learning based and they collaborate together to produce a final result for the customer, which is, as I said, this is malicious or this is not.
3:30One funny thing, by the way, Mike, about that is the two founders of Kevlar, so myself and our CTO, we are machine learning engineers. We don't come from cybersecurity. We literally come from the AI space. And we precisely thought that we could bring something over. We can design a unique AI system that is able to solve for that specific problem we described.
3:50Mike Butcher:Very interesting. So it seems that you're part of that generation that's building these new startups from the ground up with AI. So I was looking at your platform and it claims to be able to respond autonomously in about three minutes. What happens in those three minutes? Yeah, that's a great question. So imagine you have an alert that comes in, right? Like imagine that's, I don't know, a phishing campaign or an endpoint situation that arises somewhere inside the organization environment. The AI gets the alert to start with, and that's where the countdown starts. That's where the zero second starts, essentially.
4:31And then what the AI does is it will collect data that it requires. So, for example, it will connect to the different systems of the organization. It will connect to the SIM. It will connect to the EDR. It will connect to past investigations that it has run itself. And essentially, it will gather all meaningful evidence to be able to say whether, again, that's something malicious or not. In the scenario of an ongoing attack, for example, the AI would not stop there. It would also generate a path to remediation. It would say, okay, you know what, this is clearly a malicious case. We should block that IP.
5:08We should remove that email. We should re-image that server. And so not only does the AI collect all the data, give us a final outcome on whether that's malicious or not, but it will also generate a recommendation of actions to, A, avoid that happening again in the future, and B, put a stop to the situation.
5:27Mike Butcher:I see. So you're trying to say that the step change here is it's actually trying to deal with the problem as well? Absolutely. Compared to previous waves of technologies, these were static technologies. You had to build playbooks. You essentially had to instruct a robot what to do and what not to do. So, for example, you would nest a bunch of if-else rules saying, if that happens, do that, otherwise do this. But that does not scale. And on top of that, attackers will never use exactly the same path, which means that you're always trying to catch up with folks that will try to be smarter than you are.
6:00The nice thing with AI is that it can be a bit autonomous. It can figure out stuff by itself. It can pick up weak signals that you could not anticipate while building the playbook. And that makes it much harder to evade. And that being said, autonomy, I think, needs to be balanced with something else, which is trust. You cannot have an autonomous system if you don't trust it. And I mentioned that we have nine machine learning models. Well, we have one called the Graph AI, whose sole responsibility is to orchestrate the investigation in a way that's explainable. So that for you as a human analyst, it's absolutely easy to understand why Kevlar reached the conclusion, what steps it went through and what actually triggered it after each step that it did.
6:43I see.
6:44Mike Butcher:So it's pretty 360 degree solution. Now, the reason we're talking is that you've now raised a 30 million dollar funding round led by Partec and ForgePoint Capital with EQT Ventures participating. and I'm delighted to say we're also joined by Damien from ForgePoint Capital, Damien Hohner. Now, Damien, can I just bring you in now? Perhaps you could unpack what you saw in the company in terms of investing. Sure. Thank you, Mike. So we are actually doubling down our investments. So we co-led with equity the last round and we're really impressed by the progress in the last year. I think literally for us, a couple of things.
7:30So first of all, in cybersecurity, a lot of companies tend to retrofit AI inside, in a second cyber stack, essentially, you know, updating playbooks and stuff like that, which is not truly autonomous. So the first thing I really liked about Kevlar, the team is a truly native AI company, not retrofitting but literally with no prior bias and providing a truly autonomous you know a solution and that's really unique in the market so really like that secondly the team the team basically is commission of you know all the rights things for us highly technical driven ambitious immunity coachable at Fortune Capital we are trying to spot you know we launched the European fund I'm leading, we're trying to support European companies with the potential to become global champions.
8:22And we've mapped all the competitors in the US and we found the solution that Kevlar was superior technically. So by combining both, you know, Knowledge Graph and LLM, it provides more consistency than the competitors in the US. So we found a unique company in Europe with a better platform and the potential to be a global leader in the space. So that's why we invested first a year ago and a year after, you know, they've been delivering on all fronts. So essentially commercial traction with leading clients across the globe, not only in France, but across Europe, in the States, Germany, UK and so on.
8:56Both with large corporate and managed security service provider. And they're already seeing about improving the platform, essentially. So they led with investigation, what is typically what a level one analyst does. and now they're morphing toward the full spectrum of the work in security vision centers so level two which is in the investigation itself and then the threat detection and then the level three which is remediation so essentially now they provide you know a full-fledged platform revolutionize the AI using AI to virtualize SOC and improving the output basically.
9:34Mike Butcher:Right I see and it's It's clear that they've obviously got a good solution. They've got some customers, Mercedes-Benz, Sodexo, Orange Cyber Defense, Atos, etc. But, Ahmed, I know that there are also startups in this space. There's Dropzone AI, Radiant Security, and you've got some big competitors like CrowdStrike and Splunk, for instance. How are you comparing yourselves to those solutions? It's a good question. I mean, first thing is, and again, this is coming from a person that is not from cyber originally. I'm a machine learning engineer, as I said. Cyber security is a weird space where it just feels like everyone is a competitor to everyone else.
10:18So I think putting some nuance is always helpful. CrowdStrike is massive. Palo Alto networks are massive companies. They could be seen as competitor to almost every cyber security startup on Earth. but to come back to your question the reason why our customers keep choosing us and we've been compared to all the names that you have mentioned the reason is when it comes to security operations, when it comes to autonomous systems, again trust is important and when we say trust it means two things one, the ability to understand what the AI is doing and the ability for the AI to be consistent and two the ability to measure performance the ability to compute the accuracy of the system.
11:02And so that metric is of the utmost importance. And so we do have the best accuracy so far in the market. Again, we've been benchmarked against all our competitors. And what comes consistently, what comes out of the benchmark is that our customers find that we have the best accuracy. We have the lowest false negative. And the false negative rate is particularly important because the way customers are using the tool is whenever Kevla.ai says something is benign, they would dismiss the error they would not look at it at all which means that imagine what happens if the ai actually makes a mistake and that actually this is something that is malicious but that the ai wrongly tags as not harmful um then you're missing you're creating a hole in the defensive posture of the organization you are supposed to help and so in particular the false negative rate is very very important to our to our customers and yeah they've simply consistently seen a much better false negative rate a much better accuracy with kevlar than the other systems I see.
11:59Mike Butcher:Damien, presumably you also looked at the competitive landscape and thought that perhaps there's going to be potential for down the track, maybe exit to one of these big companies. Or do you feel that Kevlar's got the capability to go all the way? So two parts to my answer. So first of all, I think ultimately, as Ahmed mentioned, you always have pendulum swing in cybersecurity between going for the large platform CrowdStrike, Palo Alto Network, and so on. And this platform wants to tell you that they can do everything. The reality is that they lack the agility and the needfulness to essentially anticipate threat and so on.
12:45So essentially, I think, you know, it's easier to deal with one vendor, but you miss a lot because they don't have the capacity to innovate as much as a startup like Kevlar. So I think first step, Kevlar is already in a journey towards becoming a platform on its own. So we started the investigation, now detection remediation. So the first part of the journey is being to be themselves platformizing, if you will, their offering. And then on that basis, two options. I think they can potentially go all the way. and I think if and when the market reopens, I think you can see potentially a public market exiting.
13:21That's the scenario as they grow and there have been a number of companies out of France like Datadog and others who have been really successful in leading by technology and platform and then eventually getting to the market in the US. And the other side indeed, there might be consolidation in two steps. So actually Kevlar could be itself acquiring some type of equipment they're offering. And also, yes, definitely those companies who are desperate to reinvent themselves, you know, by retrofilling AI and need a truly AI-native solution, I'm sure we'll be already looking at, you know, options in the corporate development team to try to improve their offering.
13:57And I think KFDA will become a very attractive target for those companies. So I think, you know, So for us, we're really there to help them realize their true potential independently. But I'm sure given how relevant they are in the market, there might be some unsolicited M &A interest before that. If not, we go all the way to potentially public market exits.
14:20Mike Butcher:Right. Well, covering all bases, I suppose there. But Ahmed, I mean, the world is just so uncertain now. And there's cyber attacks every day. and especially now, as we know from state actors, to what extent do you have, does your system able to deal with these really quite difficult attacks now? And do you see that your solution is also as maybe a kind of Trojan horse into the cybersecurity sector, that you start off with this ability to deal with alerts, but then you can build out the product into different aspects? Yeah. So two questions. The first one is how our system in particular can help detect more intricate system, more intricate attacks, whether they actually originate from state actors or just large organizations that want to do harm.
15:15The first thing is, again, one has to really understand how SOCs operate. Up until now, they were very manual, very labor intensive. And we're not dismissing the labor part by any means. We don't think, for example, that AI is here to replace humans. I think that that's a mistake. But that being said, we think that AI can drastically enhance our own capabilities as humans. So instead of us dealing as the front line with every single alert being drawn into all of that, we now have an AI system that sits on top of whatever stack we have that is able to investigate at least as deeply as a human would do themselves.
15:53But that does that at a fraction of the cost and a fraction of the time as well. And so that means that now you can get a 360 view of what's happening. Now you have an AI system that can run pattern recognition at much bigger scale than one can do. And that, again, opens the door for massive possibilities. That's one thing. The second thing is we just react much faster. We just look at every single signal that we see compared to humans that, because they are droning, we immediately need to prioritize. There are some alerts that are simply not investigated because of lack of resources. That's not something the AI suffers from.
16:32So even the weakest signals and the realistic scenarios of attack today rarely generate a massive alert. Most of the time, it's something that happens under the radar until it's too late. So with AI, because of its ability to be exhaustive in its search, we can make the lives of the attacker a bit harder. So that's literally what we're working on, rebalancing a little bit the situation between attackers and defenders. And then the second part of your question was, is Kevlar some sort of a Trojan horse that starts with investigation and want to move to something else? And the answer is definitely yes.
17:04The first thing we want to do is we want to replace the SOC at the center, essentially. The way we see security operation centers is they have a 360 view on what's happening in the organization. They can see the behavior of employees. They can see what servers are ill-protected, what alerts, what detection systems do not function as well as intended. But the problem is because they're drowning in alerts, they're unable to do anything meaningful out of that. And so now with Kevlar, one of our missions is what happens if we start correlating alerts with one another? What happens if we unlock the ability to correlate an alert from today with something that happened six months ago?
17:44That's a wet dream to many CISOs, but that's something that was completely unthinkable up until very recently. And so the AI brings natively this ability. So now what we're actively working on is becoming, as Damien said, a platform that draws into the intelligence we generate from investigations to actually morph into a detection platform, into a remediation platform, and bring the value much higher in terms of the ROI that our customers perceive.
18:08Mike Butcher:I see. So, yeah. So you start with one aspect of the of the problem and then you can start working on other aspects. And as you say, it's very interesting that the the AI can start to surface data about the attacks that previously would have been invisible or just hard to track and hard to trend in the past. Absolutely. Damien, from your perspective as an investor, how do you see the cyber world changing now that AI is really so much on the map? So that's really a sweet spot. So not only we're an investor, but we are probably leading specialized fund focusing on cybersecurity and AI. So definitely that's the perfect question for us because one of the key themes for us is two things.
18:55It's not only cybersecurity, it's AI for cybersecurity, what Kevlar does essentially. So you have to fight AI with AI as the attack becomes more sophisticated and so on. So that's one aspect. The other aspect is quite relevant is also cybersecurity for AI, because AI becomes an attack vector essentially. So you deploy all these models and so on. And what used to be called shadow IT now shadow AI, where potentially some data is exfiltrated. or if you look at a platform like Hugging Face, which is a repository for open source LMS, 60 to 70 % of the models there have some kind of vulnerability. So I think for us, it's really core to what we do.
19:38So we are essentially investing in cybersecurity for AI and AI for cybersecurity. So for us, it's paramount to investment in this. this and we do you know produce a lot of research and try to anticipate basically the market trends and we had actually mapped where to invest in the SOC and realized that the two areas for us to invest was not in the SIEM, security management but really on the AI SOC automation what Keva does and also on the data ingestion pipeline essentially because we can't really you know innovate in the mentioned Splunk before. Splunk can pile up features if you will, but if you truly innovate, you need to go beyond that.
20:19And I think that's where AI comes to play either for the investigation or mediation or for the data injection.
20:26Mike Butcher:Right. Well, it's clearly a changing market. Now, Ahmad, you've raised this$30 million. What do you, very briefly, what do you plan to do with it? Well, three things. One is bring our vision closer to go to market. I've mentioned that really what we're after is not being an AI stock analyst. We don't want to be that. We want to be something much bigger than this. We think we can drastically impact the way we do defensive security. And again, I've mentioned how we intend to leverage the data that is unique to us, the data that we generate, the graph that we have, to actually get back to customers with insights, to help them adapt their posture in a proactive manner.
21:09So that's the first thing is continuing to deliver on the product. The second one is continuing to have happy customers and lending additional ones. from a go-to-market perspective, as Damia mentioned, we work with two types of organizations, very large strategic accounts, like hundreds of thousands of employees. And on the other side, we work with MSSPs as well. It's critical for us to continue winning deals, to continue pushing our system to production, because A, that's how we learn, that's how we get feedback, and B, that's how you make happy customers. And so we'll continue to do that. And the third point is, in particular, expand to other markets.
21:43It's critical for us not to be a French solution, uh we're not dismissing france we're not dismissing europe by any means we're proud to be europeans we'll continue to double down on that but we do think of our solution as a solution to a global problem and so winning in europe and in the us is absolutely key and we will double down on both
22:01Mike Butcher:geographies for the year that started yes well of course the uh that is the correct answer the incorrect answer would have been uh go out and buy a lamborghini but you're a very sensible man, I'm sure. But well, that's all the time we've got right now. So for now, Ahmed Ashak, CEO, co-founder of Kevlar and Damien Hano from ForgePoint Capital. Thanks for joining PathFounders.
From the publisher
Qevlar AI says it can deploy AI to turn alerts about cybersecurity attacks into data that was previously invisible. Pathfounder’s Mike Butcher speaks to Ahmed Achchak, Qevlar AI Co-Founder and CEO, and Damien Henault, partner with Forgepoint Capital, about how AI is changing cybersecurity.



