Go back

Haydn Brooks - Cybersecurity Start-up, accelerators & raising venture capital

0m 0s

Haydn Brooks - Cybersecurity Start-up, accelerators & raising venture capital

In this Zero Hour podcast episode, host Carlo Effult interviews Hayden Brooks, CEO and co-founder of Rys Ledger, a platform that enables companies to check security across their entire supply chain with minimal staff. Brooks grew up in West London and studied biomedical science at Imperial College, focusing on neuroscience before pivoting to cybersecurity. His career began at KPMG, where a project on supply chain security for a large bank sparked the idea for Rys Ledger. He later moved to Deloitte to focus exclusively on supply chain risk. Brooks left a consulting startup on a Friday and launched Rys Ledger the following Monday, driven by self-imposed public commitments and guidance from VC friends. He joined two accelerators: Hot Zero, a week-long course, and Sylon, a three-month intensive program that helped him pitch hundreds of times and raise initial venture capital. Brooks stresses the importance of pitching to everyone, iterating on feedback, and demonstrating execution by securing early customer interest. Finding a co-founder was the hardest part, taking four to six months; he found his through a flatmate’s friend. Brooks describes the ideal startup team using the hacker, hustler, hipster framework, where each role—coding, business development, and marketing—complements the others. The conversation highlights the challenges of building trust with a co-founder and the necessity of saying "yes" to every opportunity to generate luck.

Transcription

8869 Words, 47690 Characters

English
[Music] Welcome to the Zero Hour podcast sponsored by Beecher Madden. The podcast that gives you the insight, techniques and tools into top yes from the Cybersecurity, governance, forensic and data world. [Music] [Music] Beecher Madden are recruiters for Cybersecurity and corporate governance professionals leveraging our long-held relationships, industry knowledge and data-driven approach we help companies and candidates make better hiring decisions. [Music] Welcome to the latest episode of the Zero Hour podcast and as I'm starting a new podcast today, your host is one of the SC Magazine's top 50 women cyber security it's Carlo Effult. In today's episode we are joined by Hayden Brooks. Hayden started in a big four environment working in cyber risk mainly focusing on supply chain and third party security. The Pinyi saw in a difficulty clients were having drove him to co-found Rys Ledger. Now as CEO he developed the product through Sylon, the Cybersecurity London Accelerator and has now raised their initial venture capital investment to expand the product globally into the market. This exciting platform enables its customers to check security over their entire supply chain with very minimal staff. In 2019 he was recognised as a Forbes 30 under 30 member. Hope you enjoy it. [Music] So today I'm talking with Hayden Brooks who is the founder of a company which I love called Rys Ledger and I've known Hayden for a couple of years now. So I think this is going to be a really good story of around a great startup journey. So let's start with you. Where did you grow up? Hi Carlo. So I grew up in West London as well. I kind of moved around a lot as a kid. So the first kind of 10 years in my life was spent around Brent Foods and Middlesex and then the second half out in Buckinghamshire in a place called Amisham, and then the last stop on the Metropolitan Line. I know it very well. University, sorry? I know it very well. Yes, the Metropolitan Line after my Amisham painful. It is, yeah, it's a nice place, though. A lot of countryside and greenery. And what about education? Yeah, so I went to a grammar school at Amisham which was the reason why I think my parents moved out there. And after that, I ended up at Imperial College studying biomedical science for three years as an undergrad. So I was back into London. And within kind of biomedical, there's various different areas you can specialise in. And I spent the final year focusing on neuroscience. So I think my thesis was on probably four or five years ago now. I'm probably going to get this wrong, but it was on looking at new drug targets for a certain type of brain cancer. Wow. Yeah, something completely different to secure. Well, it does sound very different, but is it that different and the similarities or things that you've fought with you into security? Definitely, and so much that I suppose it, you're studying science. So you're kind of taught from the get-go all about the science of it method and critical analysis and logical thinking. So suppose a lot of the soft skills you bring over to your working life and directly applicable within security. But none of the technical skills like pipetting or doing any of the analyses or fish analysis. I kind of remember all the names fluorescent hybrids, in situ hyperalization or something. All of that stuff I've completely forgotten. I think most people probably have, right? Yeah. So where did the idea for risk led to come from? Oh, good question. So when I started my career, I started as a graduate at KPMG. And the very first project I had was looking at supply chain security for a large bank in London. And whilst running that project or being involved in that project, I came up with this idea for kind of combining the process or boiling the process down to something a lot simpler and easier around sharing assurance between companies. And that was the kind of core stem of the idea. And then from there, it kind of developed over the next few years until we launched risk ledger. Okay. So how long were you with KPMG for? Not too long. So there for just under two years, I think, as a grad. And they, the kind of the big four, go through boom and busts when it comes to kind of consulting work. So when I joined KPMG, they were on quite a large growth trajectory. And then two years later, they were unfortunately kind of shrinking the team a bit because I think the work, some of the work could dried up. So from there, headed over to Deloitte. Okay. And what did you do with Deloitte? Similar thing. So I joined their cyber risk team. And I was within that team. That was a team of 15 when I joined a bit later on. They basically combined the cyber risk team with the consulting team and the consultant team was a much larger team. But within the cyber risk team, I focused purely on supply chains. So all of my projects were around helping clients understand the risk from their supply chains and then helping them to mitigate that as well. So what made you think I'm going to go out and create this product on my own? Did you, did you consider doing it within Deloitte or within KPMG? Was it always something you wanted to do for yourself? To be honest, I don't really know. It was all kind of a big blur. I definitely did consider doing it with one of the big four, but I don't think because it's a technology products, as much as I love the big four, they're not really geared for building technology. They're not a technology firm. So there was always kind of that in the back of my head saying if I'm going to do this properly and I want to do this properly, I'll need to leave and set up a company and do it kind of solo. And with a co-founder and a team obviously. But there was no kind of trigger moment or no overarching right now we're going to do this kind of thought it was very much. Yeah, just over a few weeks built a pitch deck and then from there it kind of all spirals. Well, that's a really interesting point because lots of people have ideas or have dreams of having a business, but leaving the security of a full time well paid job. Or actually just getting the confidence to take that leap. That can take people years. Was there a moment where you just realised it was happening? How did that come about? Yeah, so I'd actually left the way to join the startup myself, which was a consulting startup. And I left that startup on Friday and then with full time on wrist ledger on the Monday. But throughout kind of the few months before that, I'll pry to that. I had a couple of friends who worked in venture capital, so they walked me through kind of what a technology startup involves a lot of the stages that you need to go through and want to be able to build a company. And I found that really helpful because I kind of set the ground and gave you almost like a framework to work against. So you're able to break down this huge task of building a company down into these kind of individual kind of segments of work. And then in terms of I suppose the confidence to take the plunge to be honest, I've always been the type of person who just I tend to tell people I'm going to do something. Even in my head, I don't think I'm going to do it. And then because I've told people I kind of think, oh, I have to do it now. So you end up kind of forcing yourself into doing it. So I'd say that's probably the way I went about starting wrist ledger, but very much was left left a full time employment on Friday. From the Monday onwards was was yeah full time over a sledge. Wow. Now you went through was it two accelerators. Kind of. So the first accelerator we did, which was actually before I went full time was something called hot zero, which was a week long course sponsored by DCMS. And it helped, I think it was run by the same people we run cyber London, so Grayson Jonathan and Kirsten. And the idea behind that week on course is just to give you an introduction into entrepreneurship into building a company specifically within cyber security. And give you some guidance around how to write a pitch deck and kind of the very basic fundamentals that you need to you need to learn quite quickly in order to be able to progress. So did that and that kind of gave me a flavor for what I was getting myself into and then got accepted onto silent. So silent is a start to accelerate to run out to Pam is Smith. And that's Jonathan in grace of the co founders. And that's a three month long accelerator that basically takes cyber startups. And then for three months helps them shape their value proposition, introduces them to investors, to central clients. And then you go through kind of day after day after day of speed mentoring. So it's kind of 20 minutes with each mentor really full on. And I think before I started silent, I'd maybe pitched 10 to 20 times by the end of the three months. I must have been near a four to 500 pitches. And so you really, yeah, you kind of see yourself and he yourself develop over that time period, which is absolutely great. And it's in a demo date where they invite a load of attention investors in London into a room and get three minutes to pitch, which is my first taste of a pitch that's kind of encapsulated with a timeframe. So you had to get it all out in three minutes, which is a lot harder than it sounds. And yeah, that kind of off the back of that we managed to raise our first investment round. So that's that definitely helps launch us into into what we are now. Brilliant. So how do you go about getting accepted into something like silent. Yeah, so there's a huge amounts of information on this kind of online. It's a similar process. So silent investor money. So they invested 15,000 pounds and took some extra money for that right at the very start. And they're typically the first external investors that a company will have. And so they kind of go through the same process that a traditional investor would when they're assessing a company. So they look at kind of two or three things primarily. So firstly, the founding team. So do they believe that the founding team are going to take this forward and are going to deliver a company at the end of it? And they're not going to give up after a year. And they believe that the founding team are smart enough to kind of almost pivot around any challenges they come across. And the second was the idea. So although that's definitely kind of put in a second position to the founding team, they do look at the idea whether it's viable, whether you've kind of thought through the value proposition, whether it's reasonable and something that they think kind of the market will like. And then yet the third kind of thing that they would look at to that is almost execution to date. So the strange thing is when I first looked at starting a company, a lot of people think you can come up with an idea or a pitch deck. And then investors will throw money at you if it's a good idea and you have a background in whatever the idea is in. That's not generally the case. So you need to somehow kind of show a track record of having delivered against deadlines and having delivered against. Kind of no framework around it. That's really bad way of saying it. But almost being left alone to deliver work without having somebody above you telling you how to deliver the work. And kind of that execution and proving that execution gives them comfort that when it comes to kind of solving a problem in terms of let's say supply chain. So we're going to solve supply chain that you can actually break down and progress down it without anybody telling you how to. That makes sense. Yes, no, that does make sense. Although that must be quite hard to prove. How do you go about demonstrating that you can work in such an autonomous way? Yeah, a lot of it is just speaking to people. So when you first come up with the idea, you'll have an idea and you'll think it's the best idea on the planet and you won't want to turn you want in case anyone else steals it. And that's definitely the wrong way to think about that. So the idea that you'd first come up with is always going to have to be molded and changed and reconfigured based on feedback. So the best bit of advice I ever got was from a gentleman called David Chan who just said you pitched to everyone. Whether it's your parents, whether it's colleagues, people you meet on the street, just tell them what you're up to, pitch to them and then listen to their feedback or their advice on how you pitch it and what you're pitching. And that helps over time. It helps try to develop the pitch, develop the value proposition you're bringing. You start to realize there's all nuances to certain parts of what you're trying to do that. Maybe other people can see that you can't. And you're showing that track record of having developed the value proposition in the pitch over time. It's one way to show execution and then the second way would be to actually find customers who are willing to back that vision. So before starting on silent, we had I had spoken to a number of kind of CSOs. They'd all said, yeah, this is a great idea. And when you're progressing with it and when the text built with love to be involved and trial it. And having kind of people from the industry back you up and really buy into that vision from an early stage really does show that you can execute it against it. And you can get people bought into what you're trying to do without you having even a technology product to sell. So there'd be the two ways that I do. And then the third way would be find a co-founder. So it's really hard to raise investment if you don't have a founding team. So if you're a solo founder, you can do it, but it's exceptionally hard. And VC's typically won't invest in solo founders. So the first kind of hurdle is trying to find somebody who's willing to work for free or leave their day job to join you in a startup that typically has no money, no salaries and persuading them that it's the right thing to do. And yeah, that's probably the hardest part of starting a company finding somebody who compliment your skill set and who is willing to buy into that vision just as much as you are without paying them. For example. So how did you find yours? So I was looking for us six months and I got accepted onto you. There's a number of accelerators and kind of programs around London that try and help facilitate that. So one being entrepreneur first. So I was accepted onto entrepreneur first and a few others. And it turns out after about four or five months of looking we actually subletted a room in our flat. So one of my flatmates moved out a couple months to Australia for a succumbent. So we subletted his room and my now co-founders friend moved into the room. And I was introduced to my co-founder through him and at the time my co-founder was just finishing up at university. Was a developer. So it was kind of a perfect opportunity for him to leave and go straight into a startup rather than me. And having to have somebody to leave the day job or build a startup alongside somebody else working full time. So that sounds really fortunate. But also if you were looking for four to six months, that feels like you put a lot of effort in. Yeah, it honestly is the most scary thing you'll ever do. It's almost like dating. It accepts. When you're dating someone you might see them two or three times a week. A bit more if you've kind of been dating for a while. Your co-founder, you spend nine to ten hours a day with, you'll speak to them every day, every weekend. They see the highs, they see the lows of what you're going through at work. Just the relationship you have with them is so intense that it can be quite scary that first trying to meet people and trying to gauge whether or not you can actually build a company with them. In terms of like luck, it definitely is, yeah, a lot of luck came into it. But I'd say it was also you have to say yes to everything. So a lot of times you'll be invited to an event and you don't really want to go. It's a Tuesday evening or something and you have a little work to do. And it was just learning to say yes to everything and going out and speaking to people and forcing yourself into situations where this luck can happen and where you kind of find these opportunities, where things like somebody moving into the fact and introducing to their friend can kind of happen. So yeah, it's partly luck and then partly just forcing yourself out there and trying to generate as many opportunities as possible. We always used to say in my company, the harder you work, the luckier you get. Yeah, exactly, exactly. So I mean, that's a really good point about how much time you have to spend with that person. But also the amount of trust you have to put into that person too. How have you gone about building that trust between the two of you? Yeah, I think again, it's kind of done over time. So you can't really expect to sit down with someone and trust them explicitly from day one with Dan, my co-founder. So the reason why I knew it would work pretty much immediately was he was the first person who I sat up with, he kind of pointed out all the flaws in my plan and where everything could go wrong. And that was quite refreshing and nice to hear somebody who was actually kind of critically analysing what we were doing and coming up with ideas for themselves. And I'm really humbled that he joined because he's twice as smart as I could ever be. Which yeah, over time, you see them deliver work, they see you deliver work and you kind of build this trust around. Okay, well, I've seen him get out of some quite kind of tough spots on the tech side. He see me get out of some quite tough spots and mistakes on the business side, so you kind of build up that trust and rapport over time. Now one of the things you mentioned was finding someone that compliments your skill set. And I think it was you that introduced me to this phrase, the hacker, hustler, hipster, kind of trio. Absolutely, yeah. So how does one go about identifying where they fit? Because you know, a lot of people that have that entrepreneurial spirit generally think they can do it all. So how do you how do you go about picking your weaknesses? Yeah, the only way to really find out is to try and do it. So I suppose there's there's trying to multiplancer that. So the first would be that the hackster, hipster, hustler, kind of tracotomy was I can't remember the gentleman's name who came up with it, but it's definitely not a quote that I can kind of take. But yeah, the hack is probably the easiest one to identify because they have to be able to code and deliver kind of tech. And that's a still set that the only some people have. So if you're a great coder, you end up typically being the hacker. And once you get a great coder, it's not just kind of the quality of the coder right, but your ability to think of kind of quick ways around problems and be able to come up with solutions quickly that might not be perfect, but that do the job at the start. And then in terms of the hipster and hustlers, so the hipsters typically are marketing person. So they love basically getting the message out there speaking to as many people as possible. They usually are guru when it comes to digital marketing. And your hustler is basically the CEO. So somebody who goes out hustles for money, hustles for clients, and is constantly kind of putting themselves out there and trying to progress the business in one of a way in these progressing. And yeah, they're probably the hardest to differentiate between. Again, there's a lot of literature out there on how to find out which role you fit into best. But the only advice I could give is give them all to try. And then after five to six months, if you're a team of three, you've each given kind of each role to try. Have an honest conversation around what you enjoyed, what you didn't enjoy about each role, and then just try and kind of figure out which one you'd like to work in. A lot of that kind of initial kind of year rebuilding companies all about figuring out what you want to do and how you want to do. It literally is the Wild West. There's you can build a company in whatever way you want with whatever kind of framework you want. So it's up to you to kind of pick one and run with it until you want to change it. And it's right. And would you say Sylon helps you with that, that having that framework around you? Massively, massively. So that's probably the biggest value it's tolerated as brewing is that they introduce you to other people who are running companies and you get some great stories and advice of them on how to do it. And then the second part is that there are definitely certain things where you have to be disciplined in doing them. So for example, you need to up still on the legal side, you need to understand kind of how companies are built in terms of the legal frameworks. You need to make sure that's all kind of done done right and done perfectly. So there's no problems down the line. Similarly with the accounting and the tax and just kind of the structure around that and the training and discipline they provide around that kind of framework is invaluable. Image you make a lot fewer mistakes. start of the journey, which definitely then helps later on. You're not having to go back and fix things that you got wrong at the start. - Okay. And since then, I know you've had a couple of years and you've got some more funding recently. So what was that process like? - Yeah, so when full time April 2018, April, May, June was signed on off the back of that. We raised our first funding round that was led by a venture capital firm called Seacup. We had episode one ventures and village global who are a big venture fund out of San Francisco coming to that round as well and a bunch of into investors. So we used that money to hire a couple of developers and then down and the developers built out the platform of the team. Launched the platform January 2019 now. So last year about two years old. And yeah, we basically at that point got handed a term sheet which was for AC rounds from first mini capital, who are another big venture capital firm in London, the co-founder of which is Brent Hoverman, who founded lastminute.com. So once they heard the vision of what we're trying to build and the kind of the impact it could have on the ecosystem as a whole, they were pretty bought in. So they gave us the term sheet. We then all the existing investors also followed on and handed some money into the round. So we raised that round and closed it July last year. And that gave us kind of some real capital then to hire a bit of a larger team and it started to really deliver on a lot of the things that we needed to deliver on. So improving the technology, going out there to the market, customer acquisition, things like that. And I think you said to me that sort of access to investors was not really a problem. Do you think that's because you've got a great product or do you think a lot of companies experience that? Um, I think it's a lot easier to understand when you kind of realize the direction they're coming from. So the way I think about startups are they really are kind of three facets to it. Four, if you want to count operations, but you have like sales, investment, and then technology. And essentially, the investment side, the investors are there to hand over money. If you're a venture capital firm and you've raised a hundred million pound fund, you have maybe four years to deploy that hundred million pounds into startups. And so it really is their job to meet as many startups as possible and to be handing over that cash. And so from that respect, like any VC will typically take a meeting and then it's up to you in that meeting to be able to peak their interest and get across the right message that in the right way for them to be able to understand the vision and want to back it. And from that aspect, actually, I had a lecture when I was on a weekender away with Entrepreneur First, that Matt, one of the co-founders of Entrepreneur First gave around how VC is structured and their business model and what they look for in startups and why they look for it more importantly. And that really helps when you're pitching to VC is because you can kind of understand what they're looking for and it helps you shape your vision into something that they will back and invest in. And then conversely, when it comes to the sales side, you're then pitching to people who actually have me to front money to pay for a product. And they're the ones who are hard to win because they're not there to hand out money they're there to actually bring good technology into a business to solve the problem. And so that's where your kind of value proposition needs to be really sharp, really kind of well thought out and needs to be valuable to the customer of speaking to. So I always found the investment side was always a lot easier than the initial stages of the sales side. Yeah, but having said that, it also depends on the VC for me speaking to some VC firms will prefer certain types of companies over others. You have to pick the investors quite carefully. - And we're obviously in the middle of a pandemic and everyone is locked in their houses. So it's hurt. Do you think that access to funding is going to change over the next year? - Yeah, that's interesting. There's a lot of, again, a lot of news articles kind of bouncing around about this. But I don't think it's so much the pandemic, but more the pandemic is doing to the economy. And that off the back of within the tech world, there's been quite a few kind of large things that have happened over the past six to 12 months. The main one being we work in the collapse and we work's valuation when they were trying to IPO that have meant that VC firms are taking a step back in looking at companies and thinking actually what makes a company valuable? Is it just a cool kind of brand? Is it a cool bit of tech? Or is it actually a really sharp value proposition and a good amount of revenue to show that people actually really back to that value proposition? And I think over the past year, people have been moving more towards that kind of sharp and value proposition and revenue type focus against value in companies. Supplier running reviews. And it can take up to eight to 12 weeks per supplier to do that and it really slows down procurement cycles and causes a lot of pain on the enterprise side. And similarly on the supplier side, then I've seen this with every client they work with. So for them, it's a huge drain of time and resource. And they tend to basically just treat it as, oh, I've been sent this questionnaire that asked me load of security questions. I will just tick the right boxes that I think need to be ticked because I need to win this question. I need to win it now. And that's the problem that we already kind of set out to solve with RISLager. And the way that we solve it is we have created what we call a secure social network. So the idea is that organizations can join and can very quickly invite their suppliers or connect with the suppliers if the suppliers are already on boarded. And in that way, can very quickly and easily gather up all of this data. And on the supplier side, once they've created a profile and almost told RISLager how they govern their security and provided some evidence for that, they can just share that single profile with all of their clients in quite a standard way. And then we've built in a lot of flexibility between the way organizations connect with each other, that allow different enterprises to basically apply different levels of security requirements or different policies over different groups of suppliers. And that flexibility is super important because every enterprise is different. They will have different RISLager appetites and you're having to build a product that satisfies all of them. And one of the great things about that is that essentially instead of it being siloed to companies straying out to their supply chain now, ends up being almost this like tangled web of companies that all have visibility of each other's security, if the other company has given them that visibility. So the data collection is made kind of super quickly, super cheaply. And on the flip side, suppliers speed up their buying cycles kind of, usually it can cut buying cycles from two months down to kind of a day because they're able to share their security details with the click of a button. And that social network element then kind of takes me onto the vision, which is essentially that it's almost like this governance platform that every organization can join and can use to govern their security internally. And then when it comes to showing their clients through this connection request mechanism, they can just lift off the lid and show their clients what they do. But what that allows us to do is essentially provide integrations into different tool sets. So one of our investors, for example, is a director at CrowdStrike. And we can integrate with the API CrowdStrike and allows us to collect that objective data from each one of these suppliers and then show that to the clients that there have been no problems in the supply chain. And the vision is essentially to build a security operations center for the supply chain. So we'll end up with a lot of these integrations into different tool sets. We'll emalgamate all of that data. And in the scene solution, collect data from multiple kind of systems within an organization. We'll do that from multiple organizations across a network of suppliers and we'll be able to basically spot, prevent and respond to attacks on the wire in the supply chain, which is something that can't currently be done. - Wow. And I think you touched on it. Third party risk is one of the biggest causes of breaches at the moment. Do you think that's set to continue? - Definitely. And probably I would imagine get a bit worse as well. And that's the two reasons. So firstly, as with everything that's going on with the pandemic and the economic impacts, companies all look to kind of cut costs and in doing so, they might look to change suppliers to suppliers with cheaper, which inherently brings a kind of a bigger risk 'cause there's less margin for them to reinvest in security. And similarly to that, supply chains, one of those areas where it's made up of a lot of small media enterprises. And SMEs, even though they do take security seriously, they typically don't have the expertise or the budget to be able to match the security programs that large enterprises have. And so they're always going to be a larger risk. But one of the things that they can't do is typically if an SME is attacked, they might not know they've been attacked, they might not know that the data's been taken. And so you end up with a lot of kind of data breaches happening down the supply chain that aren't reported or that they never found out about. And so I'd say that kind of two-thirds estimate is probably an underestimate as well. So I'd say over the next 22 years, as supply chains start to tidy up, as you start to see increases in the reporting of these breaches, it's definitely going to grow as a risk. - Do you think SMEs are starting to understand that risk? - Yes and no. So it really does depend on the SME. To be honest, like being an SME, you have to understand that an SME's focus isn't necessarily on security. So they provide a service and their focus has to be on providing that service and wouldn't money for the business. Like they're there to make money for the company, not to necessarily kind of be the most secure. And so for them, security is always kind of second to that, that primary business goal. And most SMEs that we speak to, they don't want to be secure. It's just they don't really understand how to be. And the current kind of assurance process are just pinning questionnaires back and forth. It doesn't really help them in doing that. All it does is ask them a load of questions that they have to kind of jump through to be able to win a contract. And that's where we kind of really saw a tech platform making a huge impact. So the idea behind our tech platform is that they can sign up for free. They can take a load of security best practice that we've built into the platform. We've got a whole knowledge base that advises them on how to implement controls. And they can pretty much frictionlessly kind of implement a full security program. using risk ledger internally. So it makes security super easy for them and super easy to understand. And then it also has the added benefit of then solving that problem around showing their clients. They are taking it seriously. But yeah, it's definitely like SMEs, definitely they do want to be secure, but it tends to be a lack of budget or a lack of focus. And the fact that security is actually quite hard to maintain the means that they're not. And security is typically seen just as a cost center. Do you feel like this actually moves away from that a little bit? Being secure can help you win more business almost. Yeah, sorry, my doorbell is going off in the background. It's the theme song from Titanic, if anyone has that. But yeah, so definitely, security isn't always a cost to a business. It's not there to generate revenue. And if anything, kind of increasing security inherently, kind of comes or puts barriers in the way of people doing business. So if you imagine, if you don't have to log into a computer, that saves you kind of 10 to 15 seconds every morning logging in. If you didn't have to decrypt a file before reading it again, saves time. So an instant security is putting barriers in the way of people doing business, but those barriers then bring added benefits of decreasing the risk. And yeah, and one of the things we're trying to do with the platform is actually, is that transformation between seeing security as a cost of moving it more towards a way to differentiate ourselves from investors? So certifications did try and do this and try to write certifications, for example, companies thought that by giving the certification, that might kind of show them in a better light to their clients. And in kind of one aspect, that was correct. But in another, because these certifications basically set a baseline in this certain way, you can change the stroke of the certification, they never really kind of did change the culture of security towards towards a kind of a revenue generating culture. But throughout platform, you know, one of the things we're kind of facing is benchmarking companies. So you can benchmark yourselves against your peers. And if you're in the top quarter, you can show your clients, I'm in the top quarter. So it's it's worth you buying me over any of my competitors. It really is kind of driving that that cultural and transformational change into the attitude towards security, rather than just asking them to put in place a fire. Yeah, and that's that's almost part of the mission of what we're trying to do. Now security is obviously a crowded space. And there's a lot of I feel like there's a lot of negativity in the market as well towards vendors at the moment. So how do you think, well, how do you go about getting attention of the sea level people that you need? And how do you think other people can get their attention as well? Yeah, I think the the highest part for a vendor in the security space at the minute is getting the attention of sea so it's getting in front of that sea so to them pitch to and I can completely understand why, but there definitely is a lot of benefit to you at the minute. And I think that's because a lot of cybersecurity, I mean, it's a booming industry that's been growing over the past kind of 10 years. It's quite an immature industry. So a lot of the the kind of the new startups have followed the Silicon Valley model of high-increased sales teams who don't necessarily know the product, who don't necessarily know the value proposition. So CISOs end up being handed by by salespeople who again don't really necessarily speak the same languages then. And that's caused a huge amount of kind of end of fatigue and CISOs not really wanting to interact with vendors just because they don't have the time to or the focus to be able to. And yeah, the way we've kind of overcome that problem was really kind of finding champions in the market. So find a group of people typically CISOs who you can get in front of and that might be through your own personal network. It might be through using Starspeccelerators. It might be through events and pitched to them your vision. Don't sell it. Like tell them what you're trying to achieve. You're not there to sell a technology. You're then especially in an early stage startup. You're there to get them bought into what you're trying to achieve. So tell them what you're trying to achieve and how you're going to achieve it. And once they kind of bought into that, they will go and tell their friends about it. And suddenly you end up kind of with this top quite viral effects of people hearing about you without you needing to be in front of them. So that's definitely worked well for us. And it means that yeah, they're not being hounded by salespeople. It's actually CISOs turning to the CISOs saying, oh, how have you solved this problem? And then that CISO kind of referring them on to a supplier who has helped them or who has an idea that can solve that problem. And that definitely at the minute is probably the best way to get in front of CISOs and get your vision out there. I think that's really good advice. And the market is obviously evolving at a very fast pace. So how do you keep up to date? How do you make sure you're still learning? Yeah, I think you're a question actually because running a company you end up. So I'm definitely still I'm like a cybersecurity specialist, but at the same time I'm having to learn how to build a company which is a completely different skill set. And you end up almost living these two different careers where on the one hand I'm specialising in supply chain. So I'm constantly learning about new innovations in supply chain technology in the way supply chains work and learning from kind of speaking to clients. And then conversely at the same time I haven't to learn all about accounting and law and HR. And I think like the law or HR and accounting side is quite easy to stay on top of because you're doing it every day when you're running a company. And then on the on the kind of the side of the crypto side it's all about speaking to customers. So every pitch that we go to I'm there I'm typically the one along with the business team who gives demos. And I'm quite close with all of the customers we have at the minute. So all the feedback kind of comes through me and through that you're able to kind of stay on top of what the customers are thinking and how they're thinking about the problem. And that's really important to be able to understand that because that all factors in then to how you build the tech and your future roadmap around what you're trying to build. And so yeah, definitely kind of a lot of conversations with CSOs and customers. I listen to a lot of kind of lectures and podcasts when I can. And then it's just reading news and trying to stay on top of all the developments that happen within the security industry for sure. Have you given any thought to how you will sort of stay in touch with all your customers as you get bigger when maybe it's not possible for you to go to everyone? So I've got this attitude where it's kind of like I'll put a problem off up until it's a problem. So yeah, basically the way tech stuff that's kind of the journey tech stuff goes on is typically the first 20 to 50 customers the founding team will be quite close to because they'll be the initial customers who are helping them build out the platform, helping them shape the vision and really providing feedback into what they're building. And then after that you end up having to hire a customer success team, a sales team to support kind of the growth and then actually kind of increase the number of customers that you are servicing. And yeah, the ways that I've thought about approaching that say it tends to be I think down to the quality of people you hire in the customer success in the sales team. So we're quite fortunate in that we've got a great sales director who has a background in kind of fintech and tech startups in the financial world. And so he's able to kind of maintain all the relationships as well. And he's been an absolute star in learning about side security. He probably knows as much about supply chains as I do at the minute. So he's an absolute great in maintaining those relationships. And similarly on the customer success side we've got a great customer success lead. And she is an absolute wizard when it comes to tech and receiving feedback and holding and building those relationships. So I suppose bringing that answer background ensures it's all about kind of building a team who reflect your core values on how you want to service your customers and making sure that those core values are then trickled down as they hire people and the team grows and making sure you're not kind of falling short on that and that everybody is there to make the customers happy and to hear feedback from the customers. So we're not just giving them something. They're actually telling us how to make our technology better and then we're taking that back to the tech team and just making sure that kind of communication loop is always there and always working is probably the number one priority at least for a young tech founder. I think that piece around the right team with the right values values that match you. That's really really hard but really good advice. Yeah. Yeah and you get that a lot as a young tech founder around building a culture or a set of values within a company and people tell you to write the values down which is all great. But I think a lot of people focus too much on it in terms of their constantly thinking about it. We need to make sure we have these values. We need to make sure that we have this culture in the company and they're almost trying to force it in and that I don't think that's really how culture is built. I think if you're there and you're kind of leading from the front and you're instilling your culture into everything you do then the rest of the team around you will inherently kind of pick that up and run with it and it's almost an organic growth. The culture ends up changing with every new employee that joins they bring something new to the team. They bring a new attitude and you're able to look at things and so you end up kind of with this ever evolving culture that's always changing always improving but is built around these core principles and it's definitely good to write the very start down the night before you even hide anyone had sat down and written almost like an onboarding handbook and within that we had kind of the five or six pillars that we were looking for within people and we were hiring them. We wrote down our mission statement for example to make sure everybody was aligned behind this one one vision. What advice would you give to somebody who wants to want to sell up their own security business? Be ready. Yeah it's I if it's early stage and they've got an idea that I would say talk to some people as possible so don't be afraid to go out and pitch to people you don't have to ask people to sign NDAs nobody is going to have the passion behind the idea that you have so it's very rare for ideas to be taken but speak to as many people as possible speak to other founders speak to clients speak to investors and listen to their feedback and one of the key things and the key things that I was quite lucky in that I realised what early on is that everybody will try and knock it down at first but that's not them trying to be mean that's them trying to knock it down to see if it is a viable idea and if it's something that they would actually stand behind and get behind. So you need to be very, very ready to have people tear apart your pitch, the way you pitch it, what you're pitching. The very first pitch I gave after about 35 minutes, the guy was just ready to hang up on the call and I knew really caught him and the last 10 minutes he kind of became really interested. But yeah, you have to be ready to make mistakes in the pitch, to be able to take feedback on board and shape that into something new and be constantly iterating on what you're doing. I think that's a really interesting point because you do get a lot of negativity when you come up with ideas. It's hard to not be put off when you hear that. Yeah, definitely. If anything, you want the negativity there and I think this is what separates successful founders and I by no means yet would consider myself successful but the founders, I've met who have built businesses and ex-tid them and built really great products. They had almost this thirst for negativity and that they wanted people to tear apart their platform. They wanted people to tear apart their pitch. They wanted people to tell them how to be better and they were able to take that on board and improve on whatever they were doing and come back stronger. So yeah, I'd say that definitely is a skill that you either need to have at the start or you need to learn very quickly if you want to build a tech company. Now all of that podcast ends with 10 quick fire questions. So you need to just answer and not think. Are you ready? Okay, here we go. What turns you on professionally? Hard challenges. What turns you off professionally? Minotinous work. How do you unwind? Oh, music I'd say. So to be honest, yeah, I tend to unwind either just by chilling on YouTube or listening to music and not really doing much else. Is that where the Titanic doorbell comes from? Yes, that is. That is the best one on the alarm system we have. What profession other than your own would you like to try? Oh, I love my job. That's the thing here. It would have been a military profession I think. I would have loved to have gone into the military. Wow, okay. What activity gives you the most energy? Solving problems and leading teams would be the two that give me the most energy. Who is your biggest inspiration? I'm trying to think of a really intelligent answer to this. I just didn't have to be my parents. So I was trying to think up sort of like Plato or but I kind of imponounced a lot of the names that were coming into my head. Definitely my parents, I've seen my parents kind of run up against obstacles and my dad's got this attitude where he always overcomes whatever's in front of him. So it's kind of a yeah, that's always been an inspiration. If you had to present a speech right now, what one word would be its subject? Suppliers. You are at your best when you're doing what? Solving problems. If today was the last day of your life, what one lesson would you impart? Say yes more. If heaven exists, what would you like to hear God say as the reason he's letting you through the gates? Nice guy with a great music taste. I'm afraid I think with the doorbell, that's not going to happen. Thank you for listening to today's episode. At the latest episodes please subscribe and for future conversations reach out on Twitter and LinkedIn.

Podcast Summary

Key Points:

  1. Hayden Brooks co-founded Rys Ledger after working in cyber risk at KPMG and Deloitte, focusing on supply chain and third-party security.
  2. The idea for Rys Ledger came from simplifying the process of sharing security assurance between companies, inspired by his early project at KPMG.
  3. Brooks left a full-time job on a Friday and started Rys Ledger on a Monday, using self-imposed accountability and mentorship from VC friends to take the leap.
  4. He participated in two accelerators
  5. Key to success was pitching to everyone, iterating based on feedback, finding early customers, and securing a co-founder—a process that took months and involved luck and persistence.
  6. Brooks emphasizes the hacker, hustler, hipster framework for startup teams, where the hacker codes, the hustler (CEO) drives clients and funding, and the hipster handles marketing.

Summary:

In this Zero Hour podcast episode, host Carlo Effult interviews Hayden Brooks, CEO and co-founder of Rys Ledger, a platform that enables companies to check security across their entire supply chain with minimal staff. Brooks grew up in West London and studied biomedical science at Imperial College, focusing on neuroscience before pivoting to cybersecurity. His career began at KPMG, where a project on supply chain security for a large bank sparked the idea for Rys Ledger.

He later moved to Deloitte to focus exclusively on supply chain risk. Brooks left a consulting startup on a Friday and launched Rys Ledger the following Monday, driven by self-imposed public commitments and guidance from VC friends. He joined two accelerators: Hot Zero, a week-long course, and Sylon, a three-month intensive program that helped him pitch hundreds of times and raise initial venture capital.

Brooks stresses the importance of pitching to everyone, iterating on feedback, and demonstrating execution by securing early customer interest. Finding a co-founder was the hardest part, taking four to six months; he found his through a flatmate’s friend. Brooks describes the ideal startup team using the hacker, hustler, hipster framework, where each role—coding, business development, and marketing—complements the others.

The conversation highlights the challenges of building trust with a co-founder and the necessity of saying "yes" to every opportunity to generate luck.

FAQs

Hayden grew up in West London, moving around Brentford and Middlesex for the first 10 years, then spending the rest in Amersham, Buckinghamshire.

He studied biomedical science for three years, specializing in neuroscience in his final year with a thesis on new drug targets for a type of brain cancer.

The idea started during Hayden's first project at KPMG, where he worked on supply chain security for a large bank and saw a need to simplify sharing assurance between companies.

He attended a week-long course called Hot Zero, then was accepted into CyLon, a three-month accelerator that helped shape his value proposition, introduced him to investors and clients, and involved mentoring and pitching.

Accelerators assess the founding team, the viability of the idea, and execution to date. They look for founders who can deliver autonomously and show progress through customer validation and a co-founder.

After searching for four to six months, his co-founder was introduced through a friend who moved into Hayden's flat. They had complementary skills, with the co-founder being a developer.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.