Following the Smart Money into Black Hat
A look back at my recent conversations with four of the sharpest investors in cyber, and the themes tying them together.
Heading into Black Hat, it is clear that the two forces reshaping our industry, AI and the capital chasing it, are colliding at once.
Valuations are stretching, incumbents are writing enormous checks, and founders are trying to build durable companies on top of a technology that reinvents itself every few months. That said, the people who see this landscape most clearly are often the investors placing bets across it, watching dozens of companies rise, stall, and get acquired.
Over the past few weeks I sat down with four of them, Sid Trivedi (Foundation Capital), Ed Sim (Boldstart Ventures), Jon Sakoda (Decibel), and Chenxi Wang (Rain Capital), to talk through where the money is going and why. Below is a short recap of each conversation, followed by the threads that ran through all of them.
So, let’s get into it!
Sid Trivedi - Cyber Valuations, Moats & the Road to Black Hat
In our conversation on cyber valuations, moats, and the road ahead, Sid Trivedi, a Partner at Foundation Capital, walked through the thesis his firm has been building around for a while now, what they call Services-as-Software. The idea is to look at every task and team across cybersecurity and ask which workflows can be automated, a market Foundation Capital has sized at $4.6 trillion. In Sid’s view, that thesis is largely playing out as expected.
The workforce question came up quickly, as it always does. Sid takes a measured line, telling me “I don’t worry that long term people will lose the ability to work. I think the jobs themselves will change.”
Automation reshapes the work rather than eliminating the worker, a framing I appreciate given how much of the AI conversation collapses into fear.
We also dug into valuations and defensibility, which is where things get harder. This is the era of Palo Alto’s $25 billion acquisition of CyberArk and Alphabet’s $32 billion acquisition of Wiz, of Torq crossing a billion-dollar valuation and Seven AI raising the largest cyber Series A on record.
Sid’s caution is that big raises create growth expectations that capital alone cannot fulfill, and that when frontier labs can replicate a product feature in weeks, the traditional notion of a moat starts to look shaky. Consolidation and best-of-breed will keep coexisting, but defensibility now has to come from something deeper than a feature set.
Ed Sim - Building and Investing When Mythos Changed Everything
Ed Sim has been an inception-stage investor for nearly 30 years and has run Boldstart Ventures since 2010, with roughly a third of the firm’s investments in cybersecurity. In our discussion on why AI security is getting rebuilt, he made the case that much of the security stack is being re-architected in real time, and that the durable moats of the past, which used to last twelve to eighteen months, now erode much faster.
Ed’s blunt read on the market has stuck with me.
“The world needs more cybersecurity, but we don’t need all the cybersecurity companies that we have right now,” he told me, a line that captures both the demand and the coming shakeout.
He was an early investor in Protect AI, which went on to sell to Palo Alto Networks in a reported $700 million exit.
Two ideas from Ed stuck with me from the conversation. The first is data, where he argued that “the biggest heist ever happening right now is that OpenAI and Anthropic created their own forward deployed engineering companies,” a pointed way of naming who actually captures the value from enterprise workflows.
The second is agentic identity, which he frames as a genuine category rather than a feature to bolt on, built around ephemeral, dynamic identities rather than the static accounts we manage today. Across portfolio companies like Keycard, and Surf AI, that thesis about identity and agents is where he sees a lot of the next wave forming, even as agents remain a small share of what is actually running in production.
Jon Sakoda - AI, Cyber & Where the Smart Money Is Going
Jon Sakoda, Founding Partner at Decibel and previously an investor behind companies like Cloudflare, MongoDB, and HackerOne during his time at NEA, brought the sharpest framing on separating signal from noise.
In our conversation on AI, cyber, and where the smart money is going, he pushed back on the idea that AI alone makes a company special.
As he put it, “AI is really only magical to the extent you have a magic power.” AI lowers the barrier to starting up, which means competition goes from thousands of entrants to millions, and domain expertise becomes the thing that actually differentiates.
Endpoint is where Jon is putting real conviction behind that view. He calls it “the Super Bowl of cyber” and points to Decibel’s $100 million seed investment in Ent, founded by veterans of RiskIQ and the Microsoft Security Copilot team, as commitment sizing for a market big enough to take on the incumbents. He describes endpoint as having its own self-driving moment.
On the autonomous SOC, Jon is optimistic but patient. He likens tools like Claude Code to driver assistance for the SOC, useful today, while truly autonomous products still need to log a lot of operational miles before earning customer trust, the same way self-driving cars had to. His investment in Dropzone AI fits that arc.
Zooming out, Jon believes cyber’s best years are still ahead, and that resilience and cyber insurance may end up being larger opportunities than detection and response alone. It is a genuinely optimistic take, grounded in where budgets are actually heading.
Chenxi Wang - Cyber Investing In the AI Exploit Era
Chenxi Wang , Founder and Managing General Partner at Rain Capital, is one of the most technical investors in the space, with a background spanning a professorship at Carnegie Mellon, an analyst seat at Forrester, and operating roles at Intel Security and Twistlock. In our discussion on cyber investing in the AI exploit age, she laid out how AI changes the economics for attackers, not just defenders.
Her central argument is that vulnerability discovery is shifting from something scarce to a continuous output of computation, and that the window between a vulnerability being found and being exploited is compressing from weeks toward hours.
That reframes what a defensible security company even looks like, since strategies built around scarcity of exploits start to break down when exploitation becomes cheap and constant.
Out of that thesis comes her interest in what she calls guardian agents, AI systems that supervise and govern other AI, along with a hard look at AI agent identity as distinct from the non-human identities we already struggle with, the service accounts and API keys sprawled across every enterprise. Chenxi also had a clear-eyed view of the funding environment, describing capital concentrating at the extremes while Series B and C rounds face real constraints, a dynamic worth watching for any founder mapping out a raise. She also highlighted how cyber as a category is also tied to the broader IT and AI categories, and headwinds there could lead to headwinds for us.
For anyone who wants her ongoing analysis, her Rain Capital Insights newsletter reaches more than 23,000 readers with some of the sharpest monthly commentary on where AI and security collide.
Common Threads
Four investors, four different vantage points, and a striking amount of overlap.
The clearest thread is the death of the durable moat. Both Sid and Ed circled the same problem, that when frontier labs can replicate features in weeks, defensibility has to come from proprietary data, distribution, and domain depth rather than functionality alone.
A second thread is identity. Ed and Chenxi both treat agentic identity as its own category, not a feature, driven by the reality that agents need ephemeral, auditable identities that our existing non-human identity practices were never designed to handle.
A third is the reshaping of security work itself, whether you call it Sid’s services-as-software or Jon’s self-driving SOC, the theme is automation of workflows we have long assumed required humans in the loop, tempered by the recognition that trust has to be earned over time.
Finally, all four are watching the same bifurcated capital markets, enormous deals and record raises at the top, with real pressure in the middle. Chenxi named the Series B and C squeeze directly, and Sid’s caution about spending your way to growth is the flip side of the same coin, as it comes with potential tension and expectations among your investors.
Closing Thoughts
If there is a single takeaway heading into Black Hat, it is that AI is changing both sides of the equation at once, the economics of attack and the economics of building a company to defend against it.
The investors moving early are not the ones with the loudest AI messaging, they are the ones betting on data, identity, domain expertise, and the slow work of earning trust in autonomous systems. Whether the current valuations hold is very much up for debate. That said, it is clear that the smart money is already positioning for a market that looks very different from the one we walked into last year.
My thanks to Sid, Ed, Jon, and Chenxi for the conversations, and I would encourage you to listen to each interview in full!

