In this episode, I sit down with entrepreneur turned venture capitalist and Decibel Founding Partner Jon Sakoda to discuss the intersection of AI, cyber, and venture capital.
Jon founded IMlogic in the early 2000s, sold it to Symantec, and spent over a decade at NEA working with companies like Cloudflare, MongoDB, and HackerOne before starting Decibel. I’ve followed his writing on venture funding and dry powder for years, and this conversation was a chance to get outside the practitioner echo chamber and look at our industry through the investor’s lens.
We chatted about:
Why Decibel positions itself as the Navy SEALs next to the big platform funds
The founders-helping-founders community model and finding the CISOs who want their fingers in the clay
What separates the founders who finish the race now that AI lets anyone start one
Decibel’s $100M seed into Ent and why Jon calls endpoint the Super Bowl of cyber
Separating genuinely AI-native companies from AI washing
AI eating venture capital and why Jon thinks cyber’s best years are ahead
The agentic SOC’s move from driver assistance to self-driving
How buyers and prospective startup employees should evaluate young vendors
Where Decibel places its next bets, including resilience and cyber insurance
AI is only magical if you have a magic power
Jon’s take on AI lowering the barrier to entry was one of my favorite parts of the conversation. Yes, anyone can start a company now, but that means everyone can. His marathon has gone from ten thousand runners to a million. As he put it, “AI is really only magical to the extent you have a magic power.” Founders with bespoke domain expertise will find AI amplifies it, while tourists entering cyber because it looks like a big market are in for a rough time. This squares with what I see across the vendor landscape. The AI layer is increasingly table stakes, and the differentiation still comes from hard-won security knowledge underneath it.
The Super Bowl of cyber
I asked Jon to walk me through Decibel leading a $100M seed round into Ent, founded by the team behind RiskIQ and Microsoft Security Copilot. His answer reframed the round size as commitment sizing rather than froth. Endpoint is a massive market with formidable incumbents, and Jon argues no customer should take a bet on a startup there unless the company is resourced to endure. He calls endpoint the Super Bowl of cyber, and Ent’s approach uses small AI models similar to how computer vision works in autonomous driving. In his words, it is the self-driving moment for the endpoint. Whether prevention-first endpoint security can unseat the giants is an open question, but the logic of going big or not going at all in that category makes sense to me.
AI is eating venture capital, and cyber wins anyway
Jon has tracked VC dry powder for years, and his recent writing argues AI is consuming most of the new capital through foundation model labs and infrastructure. The surprise was how bullish he is on what that means for us. One of the killer apps of AI is hacking, and that reality has pushed what once looked like a niche industry onto the global stage. He argues the market for security products has gone up dramatically almost overnight, that investment is following, and that neither shows up yet because the numbers get reported in arrears. After years of writing about markets shrugging off breaches, I think he’s right that AI risk is finally getting security the attention practitioners have begged for.
The SOC’s self-driving moment
Decibel was early into Dropzone AI, where Edward Wu started building an autonomous SOC product in the first quarter of 2023, only a few months after the ChatGPT moment. Jon’s analogy here is worth stealing. Tools like Claude Code are driver assistance for the SOC, powerful but human in the loop, while a truly autonomous product is a self-driving car that has to log a lot of miles before customers should trust it. After three-plus years and the recent leaps in foundation models, he believes we’ve hit the self-driving moment and only a small handful of companies can do autonomous end-to-end work. Given how much tedium and data overload burns out SOC teams, this is one category where I welcome the change.
From detection and response to resilience
Jon’s answer on Decibel’s next bets resonated with me for obvious reasons. Beyond novel AI models and new data sources, the bigger shift he wants is bringing business context into cybersecurity, so the industry stops feeling like a pure threat detection and response business and starts being about keeping the bank and the lights on. He sees cyber insurance and resilience as much bigger businesses than detection and response alone. You won’t hear me argue against that case on a show called Resilient Cyber. The economic framing is exactly what security has needed to earn sustained investment from the business.
Jon and Decibel are also partnering with me on Game Day at Black Hat on Tuesday, an all-day expansion of their Founders Helping Founders event with founders and early adopters on a college game day style stage. Registration link below, and if you’re in town, come hang out.
If you don’t already follow Jon, fix that. He shares some of the sharpest insights out there on the intersection of venture capital, software, and cybersecurity.









