Everything Casey Ellis said on any show that made the record, most notable first. Each card names its show and opens the statement there.
VC rejection usually reflects poor founder communication, not investor stupidity
“My job is to understand this industry, like the market, the future of the market, where it's going, like see around corners, do all those different things. Like that's my job. And my job is to be the best in the world at that. Their job Is to be the best in th…”
Founders should exhaust personal networks before hiring sales reps pre-Series A
“Like don't think about marketing funnels or PLG or like hiring salespeople or any of that stuff until you as a founder have figured out how to tap out your existing networks. I think the bulk of the power that you're going to have pre series A is probably goin…”
Startups should never hire just one initial salesperson; always hire two
“Then I hired two salespeople, because if you're going to do that, you never hire one, you always hire two, because that way they compete with each other and G each other up.”
Hourly pen testers cannot match unconstrained crowds of adversaries
“The problem that I had with it was this idea that, like, you know, the whole reason that we're here as a cybersecurity defender industry is because of this crowd of adversaries, right? It doesn't look like one person being paid by the hour. It looks like this …”
Founders must not sell risk-reducing security products to compliance-only buyers
“Never sell security to people that don't care. If you're trying to position a product that's genuinely going to reduce risk, don't try to sell that thing to people that only care about compliance or only care about checking the box.”
Bugcrowd closed a deal with Google in its first five months
“We did a deal with Google in the first like four or five months, which was insane.”
Cybersecurity marketplaces face negative feedback loops because customers hate discovering vulnerabilities
“Network effects, like your supply-to-man ratios, like all of these different things, there is an element of land grab. That's just inherent to building a marketplace company. But I always saw that as being fairly fragile as the only thing to rely on because ul…”
Bugcrowd monetizes through a SaaS fee rather than taking bounty cuts
“So the liquidity from supply to demand basically operates as a float across the top of everything. We're charging customers for is using the platform to make the program itself happen in the first place. So it's basically a SAS like your revenue model.”
Customer acquisition was Bugcrowd's hardest challenge due to early hacker stigma
“Customers, a hundred percent. Like I was cheating a little bit on the supply side because I was already a part of that community. So I already had, you know, some degree of like trust and different things like that. And then Once you kind of drive a message ac…”
Casey Ellis refined Bugcrowd's pitch by testing it on Uber drivers
“Literally every time I got in the car, I do this. And this is how I refined my pitch. Cause it's like, if I can get this out, have them show some sort of buying intent. Not confuse them or trip them up in the process. The more consistently I can do that, the m…”
Attaching B2B products to existing budget line items accelerates enterprise sales
“Your internal evangelist, your internal sponsor, like at some point they're going to have to have a conversation with the CFO. And the first thing the CFO is going to do is open up a spreadsheet and see if there's an existing budget one item. So if you can att…”
Founders should ultimately ignore roughly ninety percent of advisor feedback
“Get people around you that understand what you're doing, and who will call you on your BS, and be a cheerleader all at the same time, and then listen to them, and then figure out, you know, the 90% of the advice they give you that you're going to ignore, becau…”
Bugcrowd’s technical co-founder built the first platform version on a flight
“We actually didn't cut code on a platform until, like, literally my technical co-founder built the first version of the platform on the flight from Sydney to SF as we were fundraising, right?”
Bugcrowd received approximately 5,000 signups in its first two months
“We had probably 5000 odd signups in the first month or two, so it's like, cool, supply side's there, we've got that part sorted out.”
Bugcrowd secured $1.6M in Australian commitments before moving to the US
“We had commitments for I think it was 1.6 million out of Australia before we flew to the US.”
Bugcrowd hit $1M in bookings in year one, $3M year two
“We hit a million in bookings in the first year. We did, I think it was three million the following year.”
The DOD’s Hack the Pentagon program validated the crowdsourced cybersecurity market
“One of the things that happened in twenty-fifteen was that the Department of Defense launched the Hack the Pentagon program. So to see, like, the DOD go out to the open internet and say, hey, like, we need the help of fifteen-year-old kids to secure our stuff.…”
Google, PayPal, and eBay pioneered bug bounty programs around 2012
“The other thing that was going on at the time was that, you know, I think it was Google PayPal and eBay. We're all talking about their vulnerability reward programs, which was what we called a bug bounty program back in like, 2012, right?”
Bugcrowd stretched a $50K accelerator check into five months of runway
“That was like 50 grand. Pretty much that just tied us over for Four and a half, five months. Got us over to SF, raise our series seed, which we'd already kind of kicked off by the end of it in Australia.”