RSS Amplifier

Audience 1st · Feb 28, 2026

The PhD Cryptographer Who Bet His Career on a Lukewarm Idea and Succeeded

0
Sign in to vote or save

Dani Woolf · Audience 1st

This episode is presented together with:

Take Control of Vendor Risk Across Your Supply Chain

SecurityScorecard helps TPRM and SOC teams detect, prioritize, and remediate vendor risk across their entire supplier ecosystem at scale.

Learn More

Aleksandr Yampolskiy was doing everything right. He had the tools, the budget, the processes - the full security stack humming along at the e-commerce company where he served as CISO.

Then one routine vendor integration blew the whole thing open. Unencrypted credit card data from other customers, just sitting there, inside a platform that had been rubber-stamped by a Big Four firm.

In that moment, he realized something most security leaders spend their careers trying not to think about: you can do everything right and still lose your job because someone else didn’t.

That scar became SecurityScorecard.

But here’s where the story gets interesting. When Aleksandr, or AY - as he introduced himself when joining me in my studio, started telling people in 2013 that he wanted to quantify cyber risk the same way credit scores quantify financial risk, nobody was excited.

The reactions ranged from “that’s impossible” to a polite shrug. Most founders would have taken that as a signal to pivot. Alex took it as proof he was early enough to matter.

In this episode, we go deep into what this man’s journey reveals - the stuff that founders miss, that GTM teams overlook, that VCs undervalue, and that practitioners forget when the daily grind takes over.

I’m pulling on the threads - the moments in the conversation where something real surfaced, the places where what AY said carries implications far beyond the immediate topic, and a couple of spots where I think the truth runs even deeper than he took it.

In 2013, when Aleksandr started telling people he wanted to create a way to quantify cyber risk the way credit scores quantify financial risk, the responses he got fell into three buckets.

  1. People said it was impossible.

  2. Or they said they already handled it with pen-and-paper questionnaires.

  3. Or they pointed to point-in-time vulnerability scans and shrugged.

Bottom line: Nobody was excited. And nobody said, “Yes, finally!”

And that’s exactly what told him he was onto something.

His logic was simple and, I think, brilliant:

If the idea were obvious to everyone, it would mean someone else had already built it.

The lukewarm response was evidence of a gap, not a dead end.

He said it plainly - when people tell him something can’t be done, that’s what motivates him to prove them wrong.

I want to linger on this because it runs completely counter to how most founders and GTM leaders think about validation.

We’re conditioned to chase the enthusiastic “take my money” response.

We treat excitement as signal and skepticism as noise.

But AY is saying something more honest and grounded:

Genuinely new ideas don’t get standing ovations at the concept stage.

They get raised eyebrows. They get polite confusion. The market cannot demand what it doesn’t know is possible.

The implication for founders and creators is uncomfortable but important.

The next insanely successful and innovative company might be sitting in your deal flow right now, getting a “pass” because the category doesn’t cleanly map to an existing market and the “buyer persona” is hard to define.

The founders worth betting on are often the ones hearing “interesting, but I’m not sure” - as long as they also carry the wound from hard-learned lessons and the stubborn refusal to let the idea die.

The status quo is the most dangerous competition in the world.

For SecurityScorecard, it’s not BitSight, Panorays, or whoever else shows up on the competitive slide in the pitch deck.

The real thing they’re fighting is the spreadsheet.

The pen-and-paper questionnaire. The rubber stamp that lets a compliance team check a box and move on, even though nothing meaningful actually happened.

I hear it in almost every conversation I have with CISOs.

When I ask why they haven’t adopted a particular tool or approach, the answer is almost never that they went with a competitor.

It’s that they’re “fine with what they have.” Or it’s just not a priority.

The free, familiar, good-enough option is what you’re actually trying to unseat.

And here’s the thing that drives me crazy:

Most competitive battle cards don’t even acknowledge it. They’re built entirely around named competitors, as if the biggest threat to your deal has a logo and a sales team.

So here is where I want to be direct with the GTM community.

Stop building competitive positioning that only maps to other vendors.

Start building positioning that accounts for inertia.

Craft messaging that makes the status quo feel dangerous, because it is.

AY lived this. He discovered a vendor breach because nobody was actually verifying anything.

The questionnaire was a performance of diligence with no substance behind it.

Your buyers are living inside that same theater right now, and most of them know it, even if they won’t say it out loud.

Someone has to name it for them. That someone should be you.

Late 2013, AY talked to about twenty potential customers and described what he was building.

Every single one of them said some version of “I love this, if you build it I’ll buy it.”

So he went and spent six months building the technology. Poured everything into it. Then went back to those same twenty people, ready to close.

Every single one of them ghosted him. Zero revenue. Zero customers. Just six months of his life spent building something for an audience that had already moved on.

This is, in my view, the single most important lesson in this entire conversation. People are polite. Enterprise buyers especially.

They will tell you your idea is great because saying “I’m not sure” feels awkward and “that doesn’t solve my problem” feels rude.

A verbal “I’d buy that” costs them nothing to give and costs you everything to believe.

It is a social reflex masquerading as market validation and it has killed more startups than bad technology ever will.

I’ve watched this exact thing hurt founders building amazing products and services - hell, I’ve suffered from this as well.

What Alex learned, and this is the part I want people to really internalize, is that you have to change the questions.

Don’t ask someone if they’d buy your product.

Ask them how they do the job today.

Ask them what they hate about their current process.

Ask about their actual behavior, not their hypothetical intentions.

Intentions cost nothing. Behavior is where the truth lives.

This is the foundation of what we do at Audience 1st.

We don’t ask buyers whether they’d like your product.

We ask them how they operate, what frustrates them, how they actually make decisions, and what it would take for them to change.

The intellectual origin of SecurityScorecard’s scoring model is not what you’d expect. It didn’t come from NIST. It didn’t come from ISO 27001. It came from a pediatrician named Dr. Virginia Apgar, who saved tens of thousands of newborn lives by inventing a ten-point scoring system that could be administered in under a minute.

Before Apgar, hospitals ran elaborate, time-consuming tests on newborns. Thorough tests that produce pages of data.

The problem was speed. By the time the results came back, some babies had already, unfortunately, died.

Apgar’s insight was almost offensively simple:

What if we traded precision for speed? What if we asked a handful of easy-to-observe questions - is the baby crying, is the complexion pink, is there muscle tone - and used those to make fast triage decisions?

It worked. It saved an enormous number of lives. And it went completely against the grain of what the medical establishment thought rigorous assessment looked like.

AY saw the parallel immediately.

Cybersecurity had its own version of the same problem: lengthy assessments, expensive audits, point-in-time vulnerability scans. All thorough. All slow. None of them giving you a useful answer fast enough to act on it.

So he asked the Apgar question:

What are the simple, observable signals that tell you whether a company is being diligent about security?

The copyright date on a website that hasn’t been updated in twenty years isn’t a vulnerability you can exploit, but it tells you something real about how seriously that organization takes its digital presence.

I am deeply convinced that the next wave of breakthrough cybersecurity companies will come from founders who are looking sideways - at healthcare, insurance, behavioral economics, supply chain logistics, even urban planning - rather than staring at the same MITRE ATT&CK framework everyone else already knows by heart.

AY calls it the beginner’s mindset.

I’d call it intellectual cross-pollination.

And the cybersecurity industry, for all its technical sophistication, is shockingly insular about where it sources its ideas.

If every reference on your bookshelf is a cybersecurity reference, you’re probably already a step behind someone who’s borrowing from a field you’ve never explored.

I asked Aleksandr about the turning point - the moment SecurityScorecard started to scale.

He didn’t give me a single breakthrough story. No big contract, no viral moment, no lucky break.

What he gave me instead was a philosophy:

You have to out-fail your competitors.

Try ten things. Accept that most of them won’t work. Find the one that does. Double down. Repeat forever.

It sounds straightforward when you say it out loud.

It is brutally difficult to practice, because the organizational immune system in most companies is designed specifically to prevent failure.

Failure means wasted budget.

Failure means someone gets a hard conversation in their next review.

Failure means the board asks uncomfortable questions at the next meeting.

So what happens is that companies stop optimizing for winning and start optimizing for not-failing.

Those are entirely different games and the second one is how you become irrelevant.

Now, I do want to push back on this slightly, because I think it’s more nuanced than the way it sounds as a soundbite.

This philosophy is easy to champion as a founder.

AY is the CEO. He can decide to be okay with failure.

The harder question is whether the culture of experimentation survives contact with middle management.

Can the product manager safely kill a feature that isn’t working without someone second-guessing their judgment?

Can the SDR team try a completely different outbound approach without their manager panicking about weekly pipeline metrics?

In my experience, most companies preach experimentation at the all-hands and punish it in the spreadsheet or silde deck.

The failure tolerance has to go all the way down or it doesn’t go anywhere at all.

After talking to thousands of security leaders, founders, and GTM pros in the cybersecurity space, this theme emerges time and again.

The industry keeps treating solving the language gap as a “nice to have” skill when it is, in fact, a strategic vulnerability.

If a CISO cannot translate technical risk into language that a CFO or a board member understands, they will be chronically under-resourced.

They will struggle to maintain executive sponsorship.

They will watch other priorities get funded while theirs gets pushed to next quarter.

And it won’t be because the board doesn’t care about security.

It’ll be because they genuinely don’t understand what the CISO is telling them.

The communication failure is the resource failure. They’re the same thing.

For vendors, this should reshape how you think about GTM entirely.

If your marketing materials, your sales decks, and your product messaging all speak the same technical jargon that the CISO is already struggling to translate for their stakeholders, you’re not helping them. You’re adding to their workload.

The vendor who helps a CISO tell their story to the board, who gives them the charts, the KPIs, the plain-language narratives they can walk into an executive meeting with, that vendor earns a kind of loyalty that feature comparisons never will.

The field has moved from technical superiority to communication enablement.

Having a car with a gas pedal means you don’t ride the bicycle and riding the bicycle is what keeps you fit.

Convenience has a cost and the cost is competence.

Let me be specific about what this looks like in cybersecurity right now, because the general statement deserves concrete grounding.

Junior analysts are using AI to triage alerts without ever developing the intuition to understand what they’re looking at.

People are prompting their way to incident reports who couldn’t walk you through the kill chain if you put them on the spot.

Meanwhile, the shadow AI problem Aleksandr raised is very real and very scary:

Employees across organizations are uploading sensitive financial data, strategy documents, even customer information into ChatGPT because it saves them twenty minutes.

Nobody authorized it. Nobody assessed the risk. It just happened and it’s happening everywhere.

On the attacker side, the picture is worse.

The sophistication floor has collapsed. AY talked about AI-powered offensive tools where you can type a plain-language prompt and generate exploit code that would have taken years of expertise to write manually a few years ago.

Deepfakes are reaching the point where you genuinely cannot tell the difference between a real human and a deepfake.

A sophisticated denial-of-service attack against a competitor can be launched for about a hundred dollars a day.

The asymmetry between attackers and defenders was already painful. AI is accelerating it.

Here is my honest take and I don’t think enough people are saying this clearly:

The industry is so drunk on the productivity narrative around AI that it is not having a sober conversation about what we are losing in the process.

Critical thinking. Foundational technical skills. The ability to reason through a problem without a model doing the heavy lifting.

AY made this tangible when he talked about his own teenagers - can they write in cursive? Can they compose a thought without a keyboard?

Look no further than OpenClaw. An open-source AI agent that went viral in a matter of weeks, racking up over 180,000 GitHub stars, while security researchers were discovering tens of thousands of exposed instances running without basic authentication, credentials stored in plaintext, and a skill marketplace that became a distribution channel for malware.

People gave this thing access to their email, their files, their messaging apps, their terminal because it was convenient. Because it saved them time. Sound familiar?

SecurityScorecard published research identifying over 40,000 exposed instances, with sixty-three percent of them vulnerable.

The very phenomenon he warned about in our conversation was playing out in real time while the episode was being produced.

AY and I are going to unpack the OpenClaw situation in detail in an upcoming episode, because it deserves its own conversation.

But for now, let it sit as proof that this is not a theoretical concern. The laziness tax is already being collected.

A lot of boards and CEOs are pushing AI adoption because they want to signal innovation to Wall Street. The stock gets a nice bump. The earnings call sounds forward-looking.

And then the CISO gets handed a mandate to somehow secure a technology that was adopted for optics, not because anyone thought through the operational implications.

I see this playing out in real time.

The C-suite announces an AI initiative. Some press happens. Investors feel good. And then behind the scenes, the CISO discovers a dozen shadow AI deployments already running in the organization, no governance framework in place, no additional budget allocated for security, and no clear documentation of what data is going where.

They are being asked to retroactively secure decisions they had no input on. It is an impossible position and it is remarkably common.

For founders building in the AI security space, this dynamic is your opening.

But the play is not what most people think. Do not just sell the CISO a better detection tool. Give them the framework and the language to push back on reckless AI adoption from the top.

The CISO who can walk into a board meeting and say “here is a quantified view of the risk our current AI posture creates, and here is what remediation looks like” is the CISO who keeps their seat at the table.

Give them that ammunition. Equip them to have the conversation that nobody else in the room wants to have. They will never forget you for it.

For me, this was the most important moment in the entire conversation. AY referenced his company advisor at SecurityScorecard, Mike Schrage, who poses a question that I think should be written on the wall of every GTM room in the industry:

Who do you want your customers to become?

Not what does your product do. Not what problem does it solve.

Who does your customer become after they work with you?

Aleksandr illustrated this with two examples that reframed everything for me.

  1. Facebook’s real innovation, he argued, was not building a social media platform. It was transforming introverts into people who compulsively overshare personal information for social validation.

  2. Google’s real innovation was not building a better search algorithm. It was turning all of us into people who type half-formed questions into a box and trust whatever comes back. The product was the mechanism. The transformation was the business.

For SecurityScorecard, the aspiration is specific and ambitious:

Yhey want to turn their customers from passive report generators - people who send out vendor questionnaires, rubber-stamp compliance approvals, and pretend that process equals security - into proactive incident responders who use quantified risk as a shared language across the entire organization.

I want every GTM leader reading this to actually wrestle with this question instead of nodding along and moving on.

Who does your customer become?

The companies that win are the ones that change how their customers see themselves.

Apple did not sell iPods by listing storage capacity and headphone jack specifications.

They sold the feeling of having your entire music library in your pocket.

They sold belonging to a movement.

That distinction, between what a product does and how it makes someone feel, is so fundamental to how humans make buying decisions that it’s almost embarrassing how badly the cybersecurity industry misses it.

Go look at the homepage of the average cybersecurity vendor right now.

Count how many times they mention a feeling, confidence, control, peace of mind, versus a feature.

Count how many times they talk about the person the customer becomes versus the technical capability of the product.

The ratio will be depressing. It is almost always specs, compliance badges, detection rates, and AI buzzwords.

The human being on the other side of that webpage, the one who has budget pressure and a board meeting next week and a team that’s burning out - that person is nowhere in the messaging.

CISOs are human beings who make purchasing decisions the same way every other human being makes purchasing decisions:

Through a messy, intuitive blend of logic, emotion, trust, and relationship.

The vendor who makes a CISO feel understood, supported, and more capable will beat the vendor with the marginally better detection engine every single time.

I’ve heard it time and again - sitting with security leaders in person. It literally is a decision criteria.

Word of mouth matters more than any analyst quadrant.

A case study from a peer they trust matters more than a product demo.

This is not sentimental thinking. This is how B2B actually works when you strip away the pretense.

AY sees it clearly. Most of the market still does not.

When I asked Aleksandr about his hardest lessons, he went straight to hiring.

Specifically, to the times he overrode his own gut feeling because someone else, an executive coach, a reference, a well-reasoned case, told him to move forward.

Every time he was on the fence and let an external voice tip him over, the hire failed. Every time.

He’s since learned to pay attention to what he calls the “faint signal” - that barely audible feeling that something is off - and to amplify it rather than dismissing it as noise.

He said intuition starts as a very faint signal, almost too quiet to hear. And most people just sweep it under the rug.

Oh, it’s nothing. I’m overthinking it.

The data says otherwise.

He’s learned to do the opposite. When that whisper shows up, he leans into it. He tries to hear what it’s actually telling him before the noise of everyone else’s opinions drowns it out.

This resonates with me on a personal level.

I’ve doubled down on gut decisions that turned out to be the most profitable moves I’ve made. But more importantly, most useful and valuable resources for my community - the people I deeply care about in the security space.

But I also want to push back on the idea in a way I think is important.

Gut instinct is not magic. It is not some mystical sixth sense. It is compressed experience - years of pattern recognition, accumulated across thousands of interactions, that you need to look at and assess in yourself and in your performance.

The reason Aleksandr’s gut is reliable is because he has spent over a decade gathering input data through lived experience.

A first-time founder’s gut might be less calibrated, because they’ve had less input.

So the real lesson is not simply “trust your gut.”

The lesson is: build a life that gives your gut something worth trusting and then have the discipline to actually listen when it tries to tell you something.

AY believes quantum security migration will be a much bigger problem, much sooner than most people want to acknowledge.

The technical core of it is straightforward:

Once quantum computers reach sufficient capability, they will be able to factor large numbers efficiently, which means RSA encryption - the backbone of most secure digital communication on earth - stops being secure.

Quantum-safe algorithms already exist. The migration path is known. But the work of actually implementing it across global infrastructure is enormous, and almost nobody has started.

What I appreciate about Aleksandr raising this is that quantum risk is one of those topics most cybersecurity conversations either skip entirely or treat as something that will matter “someday.”

But “someday” is precisely what people said about third-party risk back in 2013, when AY was getting lukewarm reactions to the idea of quantifying it.

A decade later, supply chain security is one of the most critical issues in the industry.

The pattern is always the same:

I believe this is a space worth watching closely. Companies building quantum-readiness assessment tools, cryptographic migration playbooks, and crypto-agility platforms are working on a problem that every enterprise will eventually have to solve.

If I had to distill everything AY shared in this conversation down to a single idea, it would be this:

The companies that win in cybersecurity - whether they are early-stage, growth-stage, or scaleups - are the ones that understand the human layer better than everyone else in the room.

Technology is going to keep evolving.

Artificial intelligence will get more powerful and more dangerous simultaneously.

Quantum computing will eventually break the encryption we all depend on.

Supply chains will get more interconnected and more brittle.

None of that is optional.

What is optional is the human failure to prepare.

The failure to listen deeply enough.

The failure to communicate clearly enough.

The failure to build trust before you need it, instead of scrambling for it after the crisis has already started.

Aleksandr built SecurityScorecard because he experienced a third-party risk failure personally and decided that no one else should have to feel that kind of helplessness.

That is not a business thesis born from market analysis. That is a conviction born from a wound.

And conviction - more than technology, more than funding, more than any clever go-to-market play - is what separates the companies that thrive and scale from the ones that get quietly absorbed into someone else’s platform.

If you are in the business of cybersecurity - selling it, funding it, buying it, or building it - your competitive advantage is not hiding in your tech stack.

It is in your ability to understand the human being on the other side of every transaction, every deployment, and every decision.

Read the original on audience1st.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.