TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How do startups value security?

6 点作者 chasemiller超过 9 年前
I was recently reading Jason Lemkin&#x27;s &quot;It’s Time For You To Make Security a Core Feature — Not a Tax&quot; (https:&#x2F;&#x2F;www.saastr.com&#x2F;its-time-for-you-to-make-security-a-core-feature-not-a-tax&#x2F;) article and it made me wonder how security is valued in startups. I realize that it is hard for most startups to justify spending cash on security and then I started to wonder:<p>-What equity would you give up in exchange for dedicated security audit services? (.1%&#x2F;year or something)<p>-Do you perform security audits? If so, do you do them in-house or outsource them?<p>I would love discussion from both startups and consumers.

3 条评论

rajacombinator超过 9 年前
Probably just like end users - ie. not at all, until SHTF.
brudgers超过 9 年前
The idea of getting paid in equity suggests an unsustainable business model since startup equity tends to be illiquid. This suggests that the business providing the service may not be around in a year or two or less. In addition, transferring equity to contractors will also have significantly more overhead than a cash transaction.<p>The real question is what is the value proposition of the security services? That&#x27;s necessary for sales.<p>Good luck.
评论 #10875900 未加载
dsacco超过 9 年前
I run a successful security firm, so I feel fairly qualified in saying this: your equity proposal is not financially sound. It&#x27;s a creative idea that has been considered before, but it&#x27;s not something I would consider, and it&#x27;s not something most (any?) of my clients would consider. Frankly, software security services are closer to insurance than they are to contracted software development. You have a variety of obstacles to making this successful.<p>First, investors would be concerned that the founders are offering equity for &quot;non-employees&quot; and &quot;non-core&quot; consulting services. Investors don&#x27;t like to see independent contractors getting equity to begin with - the only case they&#x27;d be okay with this is if the founders need help building the company&#x27;s fundamental software.<p>Second, your shares would be the first to be diluted when it comes time to see whose shares are not as important. 0.1% equity for a year&#x27;s retainer? That usually amounts to 12 weeks of actual work, maybe less. This is an amount they will eventually offer to full-time employees over a period of several years. How would you vest it?<p>Third, consider that if your firm is providing security audits for equity, you are self-selecting for startups which have poor business acumen (in that they accepted this deal). Your already poor chances for any equity return at all just became poorer. How long can you provide security services on a &quot;I&#x27;ll take a hamburger today and gladly pay you tomorrow&quot; basis before you run out of money and need to actually charge market rates? It&#x27;s not sustainable.<p>Finally, you are basically a de-facto investor, in that you need to select startups you believe will be winners, otherwise your equity will be worthless. You&#x27;ll have to be both an excellent angel investor with your startup bets and an excellent security provider, and this will be further complicated by the fact that only inexperience or bad founders will be likely to offer equity in return for security.<p>In other words, it&#x27;s a bad deal, most people won&#x27;t take it and you&#x27;ll probably be burned by those that do. It&#x27;s not sustainable and if you&#x27;re doing this because you want to get rich, consider that running a successful security firm and doing good work for fair market rates will get you there.<p>To answer your (easier) second question - most startups care a lot about security once users start asking them difficult questions. Then they turn to firms like Sakurity, NCC Group, Optiv, Bishop Fox or my own and outsource an audit, because they don&#x27;t have the resources for an in-house security team just yet.<p>To answer your other question, startups will start getting audits once they reach their second or third round of funding, though the savvier ones might do it once they have substantial enough seed funding. There is a sweet spot where startups know they need security but won&#x27;t bother with an in-house team - that&#x27;s where you market yourself. Alternatively, you can market your services to enterprise companies with both an in-house team <i>and</i> regular independent audits, but that&#x27;s harder for a beginning firm.<p>That&#x27;s just the broad strokes though. Some startups need to prove security competency earlier on; some try to hire security teams quickly.<p>More importantly, how much security experience do you have? What is your network of potential clients like?<p><i>edited for formatting</i>
评论 #10875894 未加载