
Agile Is Dead. The Best Engineering Teams Are Now 3 People. | Zaid Al Hamami, Boost Security
Jun 28, 2026
Zaid Al Hamami built Immunio in the early 2010s, sold it to Trend Micro, and is now back at it with Boost Security. He joins Nectar to talk about what changes when you build a cybersecurity company twice, fifteen years apart.
The conversation traces Zaid's path from coding as a kid in Jordan to running product at Canonical, founding Immunio and navigating the RASP category consolidation, and the market insight behind Boost: securing software at the speed that AI now writes it.
What gets covered:
Why "if you build it, they will come" nearly cost Immunio its shot
What Mythos actually changes for cybersecurity, and where it's overhyped
The economics of running frontier models on every pull request (hint: tens of millions)
Developer endpoints as the new CISO blindspot
CI/CD pipelines as the next supply chain attack surface
Why agile is dead and the best engineering teams are now three people
How one major airline restructured 600 developers into 200 three-person pods
Founder scar tissue from a first exit, and what ports over to the second company
Transcript
Nectar: [00:00:00] Zaid, thanks for being on the podcast. Really happy to talk to you today. I think we were talking about before, before recording, I'm a little biased of our conversation today. I wanna start where we first met and like I'm, I feel embarrassed to say this story. It's like with Immuno, right?
Nectar: Yeah. Where we're both tenants of WeWork, and which I had completely forgotten- yeah ... until you reminded me on the stage. You're like, "Oh yeah, at least you..." So maybe walk us through Immuno the company, why you started it, and what it was.
Zaid: Yeah. First of all, thank you for having me on the podcast.
Zaid: So I guess maybe just before Immuno, just to introduce a little bit myself and how I ended up there. So I, at a very young age, like many people in our industry, I fell in love with coding. So at, I remember at age 10 or 11, I was writing a lot of code. I would save money, buy programming books, spend hours programming every day, and I knew at a very young age that I was gonna spend a career building software and businesses, to be honest.
Zaid: Now the types of applications that I was [00:01:00] building, the things that I actually found interesting to build I did the occasional video game here or there, but really it was mostly the cybersecurity hacking type of tools. I just found it fascinating to be able to make computers do what people didn't want them to do.
Zaid: And so that passion stayed with me. So I, I ended up originally from the Middle East, from Jordan, born and raised there. I ended up in Canada, studied at McGill, did a degree in engineering, worked as a computer software professional for a few years, maybe 10, 12 years. Not in cybersecurity, but cyber was always the thing that I really enjoyed.
Zaid: That's what kept me in touch with tech, what I was always fascinated with, I was always reading. And now how that ended up in Immunio my last job before I turned entrepreneur was I was working for a company called Canonical. Canonical is very well known in open source land. It's the company behind the Ubuntu Linux distribution.
Zaid: And I was running product management there. And, we had, there was the Ubuntu free open source Linux distribution, but then the company [00:02:00] had a number of commercial offerings to sell to companies like Google and Salesforce and IBM, usually in the form of tools to help you manage thousands of machines, right?
Zaid: The free stuff that you can download, but then once you have tens of thousands of them, you usually need something to be able to manage that fleet of machines. And so one of our commercial products was a product that did that. And, we had built it. It was great. People loved it. It was selling.
Zaid: And part of what we needed to do was just make sure that product was secure, that you cannot make it do things it wasn't meant to do, because the whole point of this product is to manage thousands of machines. If it were accessed by a hacker or some- somehow somebody was able to subvert it, then you can imagine they'd be able to do very nefarious things to those machines, because that's what the product is about.
Zaid: It's about managing large numbers of machines. And so we would do security testing on those products. And actually one of our star engineers at the company was [00:03:00] finding flaws left and right internally before the product was ever released. And me and one of the engineers on my team were, "Okay, how do we actually...
Zaid: these are the bugs that they found, but w- we're not gonna find everything, and we're shipping and we're doing CICD and DevOps and Agile. We're releasing fast. Like before it was cool, as they say. And so how do we, add some level of security and protection? And, we, we-- what we were using at the time was something called web application firewalls, like network layer device that checks input.
Zaid: If it looks suspicious, it blocks it. That was the idea. And at the time, so 2012, 2011, that, it really was not very good tech. It was very cumbersome to manage, very difficult to deploy and configure and keep running, and it didn't really work very well. People were able to, quote-unquote, "evade these technologies relatively easily."
Zaid: Me and that engineer Mike, who became my co-founder at at Immuno had this idea. At the time, there was a company called New Relic that was quite popular and did really well that had [00:04:00] basically an instrumentation-based approach. So it was a different type of approach than just doing network layer stuff.
Zaid: We wrote a prototype. It worked really well. It looked like it could tick all of those boxes, right? And we thought that, oh there's a whole industry of these applications that need to be protected, and we think we just built something much, much better than what was considered state-of-the-art at the time, right?
Zaid: So that's, There was basically a an interest in cyber and like always connected to that field, and then a real-world problem that we faced while trying to secure a very critical application at a company. And and that, that was basically the inception of Immunio. We pitched the idea to a number of VCs.
Zaid: It got funded pretty quickly, actually. Put together a company, and within maybe a couple of years, we had our, a few really good customers using our stuff, companies like SurveyMonkey and CareerBuilder and so on and so forth,
Nectar: yeah.
Nectar: Was it hard to make the jump? Was it an easy decision of "I'm gonna leave this safe company to, to start something"?
Nectar: You had never done that before,
Zaid: right? Y- yeah. To be [00:05:00] honest, I think it-- I wouldn't say it was easy. But for me, it was always part of the path. I knew since I was a, a teenager that, one day I'm gonna build my own software company 'cause I think that's very fascinating and very interesting.
Zaid: And, a lot of the companies and entrepreneurs that I look up to that's the path they chose, and I just knew I had it in me. I think the experience that I had leading up to that point gave me the confidence. Y- I ran product management at a very successful company at a relatively, relatively young age, and we had seen all this traction, all this success, and I learned a lot along the way.
Zaid: Got to the point where I was confident that, whatever I don't know we're gonna, we're gonna figure it out. But I do think that's usually the hardest... for most people, the difference, I think, between entrepreneurs and people that wanna be or really wanna be entrepreneurs but just can't make the jump is that fear factor.
Zaid: It is always safer to work at a, a stable job, not take risk, and so on and so forth. But I think some people are just, it There is nothing el-- Like, they know they have to do it, it's [00:06:00] they have it in them.
Nectar: Yeah. Yeah, I could- ... I could definitely relate to that a little bit. Yeah. And maybe I'll share my perspective at Immunio.
Zaid: Sure.
Nectar: 'Cause I was-- We're the f- like, my old company, we're the first tenants at WeWork- Yeah
Nectar: with you guys. And I was like, this is we kept seeing the Immunio t- t-shirts, right? Yeah. The blue T. We're like-
Zaid: Yeah ...
Nectar: and your team kept growing. At one point, you guys were taking-- It felt like you were taking over- Sure ... all of WeWork. Yeah, we had
Zaid: the biggest suite, actually- Yeah ... at WeWork, yeah.
Zaid: You were like, I don't know,
Nectar: 20, 30 people. Yeah. And us, we're like a small company- Sure ... four or five people at that time. And it's funny 'cause when I was saying you're embarrassed, you're, you're-- I was embarrassed 'cause at our launch-
Nectar: Yeah ... you're like, you re- you recalled that s- Yeah
Nectar: Us being neighbors. Neighbors. I completely had forgotten. Yeah. This is e- even after we had invested in your company. Yeah. I was like, should have probably remembered that. Yeah. So yeah, and it was cr- 'cause I remember the, my thinking of Immunio back in the time "This company's on fire."
Nectar: It's like you kept hiring people.
Zaid: Yeah. So we had basically the story of Immunio was, so we had this innovation or this idea of how to do something better, and we had built it, and it, we'd proven it, and we actually got patents on it, and so on and so forth. And the year after, Gartner, the famed analyst firm [00:07:00] created a category and put us in it.
Zaid: So the category was called RASP, Runtime App Self-Protection. And there was, at the year one, there was only us and two other vendors, I think. And it gave the industry or it gave the category some form of legitimacy. This is, we're not the only ones that are thinking about this problem.
Zaid: And customers would start to ask about it. And so we, especially after we got our first or second first two or three major clients in the Bay Area and they loved the tech. The tech worked really well and solved some real problems for people. It we basically went on a hiring spree.
Zaid: We started growing the company. There was the inevitable, startups. We originally started with a developer based go-to-market. We-- So offer it for free, let developers use it, self-serve, and then try to convert some of them. Back then in 2013, 2014, so a couple years after we started, maybe, the market was still not ready for that type of thing, especially in security.
Zaid: Security was still managed. Most enterprises, it [00:08:00] was a separate function, and it was still far from developer. Kubernetes wasn't even a thing at the time. Lot of DevOps was barely adopted. It was early days. Now what happened was, maybe three or four years later by 2017 or 2016 I think a lot of the vendors, basically they-- The whole market was able to get a few marquee customers, but, we didn't see hockey stick growth.
Zaid: And it was largely because there was friction in deployment So we were selling a developer type of technology, but the benefit was when the technology was deployed to production. And today it's much more acceptable. You've got Kubernetes automation, you can deploy something, DevOps engineers are everywhere.
Zaid: But back then it was still early days for this whole transition. It became clear that, this was gonna be a very long slog of a market, for everybody. And the reality is y- we decided that it made sense to, all right, this is, it's gonna take too long.
Nectar: So you guys provoked the exit, the M&A path
Zaid: basically?
Zaid: We had... there's a number of vet- acquirers that have been talking to us for a while 'cause they [00:09:00] thought they're, the technology itself was interesting. They needed something to help actually with the Kubernetes security 'cause, if you're... the company that ended up acquiring us was a company called Trend Micro.
Zaid: I'll talk about it in a second. Great company. But these types, so they're, you can think of them as like competitors to CrowdStrike and SentinelOne and so on and so forth. They sell product that goes on servers, on endpoints, and anything that's running inside of a, like a Kubernetes cluster, for example, or they're invisible to.
Zaid: So they needed some technology to be able to monitor at the application level, which is exactly what RaaS technologies were about. So in the, I think two or three years since we were acquired, so was every other RaaS vendor, pretty much everybody, right? So the basic- essentially the category folded into a much larger category.
Nectar: There's, there was consolidation and-
Zaid: Correct ...
Nectar: so talk a little bit about the exit Yeah ... to Trend Micro. It was like 2018, '19?
Zaid: It was 2020, end of 2017, 2018.
Nectar: Yeah.
Zaid: Yeah. So like I said, we had been talking [00:10:00] to them for quite some time. We'd built a relationship and so on and so forth. Great company. It was interesting to go from like a smaller...
Zaid: So prior to starting Immunio, like I said, I was running product management at an open source company that was, about 1,000 employees, but operated very much like a startup. There's really decentralized thinking, moving fast, modern development practices, And so that was that, a small startup.
Zaid: And then within Trend Micro, which is again, I think it was a great company, great culture. But what I learned quickly is that... So most of these large companies, they have thousands of customers, okay? And it's a good thing. As companies grow, they'll have thousands of customers. The challenge though is that an inordinate amount of resources budgets, people will go to protecting that existing business, okay?
Zaid: So instead of the focus being innovation, next generation, solving tomorrow's problems, [00:11:00] it's how do we make sure we renew that biggest customer because a good chunk of our revenue comes from these. Yeah. So it, there's always this tension between, building and innovating and solving tomorrow's problems versus the business really needs these things to...
Zaid: And that leads to, and, I guess this is why, large companies have to acquire startups continuously nonstop now and in the future, this tension is, I think, both inevitable and healthy. And I realized the part that I'm definitely wired for is the innovation part.
Zaid: And so within- The zero
Nectar: to one as you
Zaid: say. Yeah ... the zero to one, one to 10, this is where, you know- Yeah ... I think is the fun part for me. Yeah.
Nectar: So after the exit you spoke about the, this market insight you had- Yeah ... the what's the, what was the market insight for Boost right after your exit like?
Zaid: It was actually essentially a lot of continuation from Immunio. Sometimes I tell people it's like the same mission. It's just, the next set of problems. So the y- one way to, one way I like to talk about it is to say, the path we were on, even from the old days of Immunio and RaaS as a category and so [00:12:00] on, was very much, Software development.
Zaid: It takes some effort to do a good job at software development. It takes more effort to make sure that software that's produced is kinda safe, secure, hardened, not easy to hack. It takes prac- it takes effort, right? And technology expertise and so on. And the insight at ImmuniWeb was that, look, we'll never be able to do a perfect job before things go to production, so let's put something in production that gives extra armor.
Zaid: That was the core insight. Now, as I mentioned earlier, these were early days. It was really there's... Because you didn't have Kubernetes observability platforms, runtime instrumentation, like it became not very easy to go from... to actually get the thing deployed and people to see the benefit was hard work.
Zaid: But in 2019, 2020, the market had evolved. There's a lot more companies doing agile and DevOps. DevSecOps was a practice. Kubernetes was, like, [00:13:00] widespread, which basically allows a lot of, for a lot of the automation instrumentation, you can actually deploy things really quickly now. And so we had, I had reached out to a lot of the people that, I worked with in, in the industry my old days, and told them, what have you tried to solve in DevSec?
Zaid: How well is it working for you?" The whole concept of can we secure software at the speed of developing it? And the answer was a resounding everybody's trying, nobody's successful at it unless you're like, Google and Apple and Meta, the big tech companies that effectively build everything in-house.
Zaid: And so the insight was that should be solved. It can be solved. We can actually bring in Google, Facebook, or Meta, Apple's sort of secure software development practices, deliver it as a service into the into every organization, deliver that as a SaaS. And that was the inception to the point.
Zaid: So the reason why I wanna emphasize that is it's basically ImmuniWeb was you'll never do a great job there, so [00:14:00] let's add some protection at runtime, at production. But then now we said the market changed, technology's changed, development practice has changed. You can actually do a pretty decent job early on.
Zaid: It's just not easy, so let's make it easy. That was the inception. Now, funny enough, I'll tie that to where we are today. The way I talk about it is So companies were doing some form of application security or the practices to make software development safe. That's like going from one to 10, you already do something, but you're trying to do it faster 'cause now you're developing faster with new software development practices and so on. But what we're seeing now with agents and agents writing code and agentic engineering is, I would say it's the same thing, it's just much faster and it's happening in a different pace.
Zaid: So it's going from 10 to 100, but it's fundamentally the same problem, which is code is being generated at a faster and faster rate. It's more complex code. How do I not slow down innovation, but yet ensure that we are producing software [00:15:00] that's not gonna lead to headline news, customer breaches, lawsuits, bad reputation damage, and so on?
Nectar: Yeah. There's so many different areas, right? Yeah. We could lead this, right? Yeah. So going back to why I'm excited with what you're doing at Boost. But I wanna talk about maybe cybersec as a whole. Sure. Because of where you're talking about this big change that's happening, and we were talking about before about, like, how Mythos is I think the best thing to happen to cybersecurity in a while, where every- it's top of mind for every CISO, right?
Nectar: Yeah. How... so the attack surface for hackers, right? Because in, in your company you're protecting exa- e- essentially against attacks. How is... I know the answer to this question, but I'm curious- ... to hear you. How is this new vibe coding this new way of building software, how has it increased that surface plane for attackers?
Zaid: Oh, yeah. I think in many ways and I'm gonna give some specific examples, but I once had to give a talk to an audience, n- none of which was in the cyber industry, and I needed to explain, like, why... Somebody asked a question, all this funding that goes into cyber companies, yet we still hear of [00:16:00] breaches what's going on?
Zaid: And and I think the general pattern is this. Technology and innovation never stops, so there's always some new standard, some new technology that catches wildfire and becomes adopted like crazy. So whether it was email the internet, mobile apps bec- was, were a thing one day where everybody wanted a mobile app strategy, cloud computing, and all the way down to agents writing code now, right?
Zaid: These technologies get adopted at a crazy fast rate when it's the right format, right price, right time, all that stuff. Security research happens at a much slower rate, okay? Research, at least until now needs these experts to spend hours and weeks and months and years trying to understand how that technology can be abused.
Zaid: So basically, [00:17:00] since the n- dawn of tech technologies get adopted super fast, much faster than the ability to find flaws in them. And so what ends up happening, you find yourself in that scenario time and again, which is we've got, tens of millions of things that have already been deployed where we're just starting to find out how hackers can breach them, okay?
Zaid: And so the industry was always like this We discover that everybody's got mobile phones, but we didn't think of mobile phone security. And so hackers start hacking 'cause it's easy, and then a mobile security industry emerges to plug the holes in that industry, and that happened for cloud computing, containers, Kubernetes, and, we can go on and on.
Zaid: I think, so now we're at the age where agents and vibe coding is the thing. It caught wildfire, okay? Faster than an industry... nobody stopped and said, "Let's make sure we build the security first." That never happened. It's just, it got deployed, pushed, everybody's using it, and now every week researchers [00:18:00] come up with new ways in which, oh, we can subvert your coding agent, and if you download this agent skill that's malicious, bad things can happen.
Zaid: Oh, and by the way, you're connecting this MCP server that does that. And so we're... I guess my point is there's nothing special just because it's vibe coding. It's just the natural way of how technology gets adopted and how security research happens and it will always be this case. Now, the, I would say that things that are specific, I think, to, to agentic coding The rate at which it's pulled is crazy, right?
Nectar: So part of it is speed, right? Where it's like- Speed ... the co- the agent's gonna go in the GitHub repo, pull up... It's not gonna ch-check the re- the repository. There's f- a bunch of malicious code in there.
Zaid: So like- Yeah, they can be subvert. Agents are very easy to sway, okay? A lot of effort has to go in to making sure they don't do what nefarious actors want them to do. And so [00:19:00] whether they're pulling an open source package that, has bad instructions for the agent whether they're, two days ago GitHub was breached. The company we all rely on for software development, they themselves were breached. An engineer working for GitHub downloaded an extension for his IDE, VS Code, and there was malware in it, supply chain attack, we'll talk about that. And, led to a breach of internal source code repos, right?
Zaid: So it, it will happen to the best of us, right? It doesn't mean that GitHub or any o- a company falling victim to this, it's just the reality is we use this tech at a rate and at a pace that, we just didn't have time to pause and think of all the security implications, and the industry now is trying to catch up and say, "All right here's all the million and one ways bad things can happen."
Zaid: Subverting agents is one, that's one way. Supply chain attacks is I think is a sleeper here. That's the one that us in the industry- Can you explain what it mean, what
Nectar: is supply chain?
Zaid: Yes. For the last I don't know, 25, 30 years, open source has been, just been growing, and growing in popularity, and we have open source projects for [00:20:00] everything.
Zaid: Your web front end frameworks, your APIs, security libraries, you name it, you're probably building on some form of open source. I've seen, And we've had examples where attackers figured out that, hey, people are just trusting that this open source project is used by people, but maybe we can find a way to inject some bad code in there, malicious code, and then wait for people, developers to pull the, that code in.
Zaid: It used to be we f- saw some examples of this in the last few years, but then in the last year and a half, it's become such a problem. Every month, hundreds if not thousands of incidents of this are happening to everybody. And it could be the, There's many variations of this, but it could be, your developer tools that you use, it could be open source libraries that you use, it could be Chrome extensions that you're adding.
Zaid: There's many flavors of that. But that is a supply chain attack. It's you're introducing something into your supply chain or into your how you build software that has backdoors and malware and sort of malicious code [00:21:00] in it.
Nectar: And it goes back to agents finding basically-
Zaid: So it could be agents, it could be humans too.
Zaid: Yeah. It's not unique to agents. But agents have the same failure modes as do humans.
Zaid: They will download open source tools. They will install stuff without really thinking about is it safe to install or not. They can fall victim to these types of supply chain attacks. And I'd say what happened was where it really started to m- So we've been researching this area for many years, and I'll talk about some of our research there.
Zaid: But there's a particular actor called TeamPCP that kind of specialized in these types of supply chain attacks, and they've b- really been causing a lot of damage since March of this year. They've done some attacks from before then, but it, since March, they've been nonstop, major breach after major breach using these types of techniques.
Zaid: And typically what happens in a supply chain attack say the common case is, Nectar wants to build this, wants to vibe code this new application for Amiral Ventures. And so he whips up Claude Code and starts writing code. And Claude at some point will [00:22:00] go and download some open source library to do its job.
Zaid: But that library is compromised. It got compromised last week by some, by TeamPCP or some s- attacker like that, where they inserted some malicious code. Now what Claude does is it'll install that package. The malware may look at, hey, what kind of keys are configured on this machine? And maybe it finds your GitHub credentials.
Zaid: And so now it goes to Nectar's GitHub repos, and it inserts code to propagate to other... So now all of a sudden, other people working with Nectar on that project, the next time they try to build a project, they get infected, and so on and so forth. So we're seeing these spreading like wildfire type of attacks.
Zaid: Tens of thousands, maybe more GitHub credentials have already been exposed. The public, like the damage that's public that we know of include things like Cisco, for example, lost proprietary code [00:23:00] bases, hundreds of them, in fact, including some of their latest AI products. There's big class action lawsuits.
Zaid: I mentioned GitHub a few minutes ago. It's kinda like a company we all trust to do good work for us. Yeah, so th- this is one example. There's many more, but in a nutshell- Yeah ... it's a very dangerous thing.
And
Nectar: explain maybe what is developer endpoint security, right? Like how does the developer fit in all of this?
Zaid: It's... since the attackers have started targeting these developers or developer infrastructures, so these types of supply chain attacks typically are targeting developers. And typically what they're trying to do, so wh- when we said developers use open source packages, attackers poison these open source packages.
Zaid: There's many ways they can do that, and then they're waiting for developers to download and install them. It turns out that you really can't just wait to, once the application is in production or once I check in the source code into GitHub to scan it there. Because the damage is already happening on your laptop [00:24:00] the second you install that package, for example, or that IDE extension or whatnot Now the damage is also done there.
Zaid: It's not just that you installed, but you... That's where you lost your GitHub access or GitHub tokens or access to some, cloud API of sorts, right? It's on your developer machine. Developer machines typically tend to be more special than, let's say, a machine in a enterprise marketing department, because typically we give developers ability to install and uninstall software.
Zaid: We don't really tr- block their network access as much because their job requires that, they download stuff, install stuff, do test stuff, and so on. And because, they generally have more privilege, like they have access to push to Kubernetes, they have access to log into, Datadog.
Zaid: And so they'll have API keys on their machines, not always stored in the safest format. So this is why they're such valuable targets for hackers. So because of this, it-- we [00:25:00] recognize that it's a unique... a developer machine is not just like any other machine. It's not Jane from marketing.
Zaid: So it needs its own... because of the unique risks we want to be able to be able to protect it, you have to take those unique risks into account. And so we developed this technology, developer endpoint security, which is really about let's make sure, let's assume breach first.
Zaid: Assume that the developer will, at some point or another, fall victim to some supply chain attack of this sort. What can you do beforehand to limit the damage, limit the blast radius, and what can you do after to make sure that, you do the right things if an incident were to happen to make sure that the damage is contained, right?
Zaid: Yeah. So typically it's key rotation and
Nectar: so on. So m- maybe it's a good, ... talking point to talk about your particular innovation with Boost, right? Because it's not just one thing. You do multiple- Correct ... interesting products.
Zaid: Yeah.
Nectar: So with everything that's going on in this world, like, how do you protect against these attacks, right?
Nectar: And it's and my sense is that you guys are also at the cutting edge of this space right now, right? It's also [00:26:00] not common for a startup of your size to have a research team and with Francois and that's- ... super focused on this. So yeah, I know it's a broad question, but like-
Zaid: Yeah
Nectar: how does Boost help their their customers to avoid getting hacked in a sense?
Zaid: Yeah. So w- first of all, we're very proud of the customers that we have. We've got some really great customers. Some of the largest companies in the US, some of the biggest software companies in the world trust us to help them build secure software and build software securely.
Zaid: Now we have always had a research team. So Francois, our VP of security research, was actually one of the first engineers to join the company. And actually he was the first engineer, it was, to join the company. And we've had a research... He's been doing, holding a research function since then.
Zaid: We've had a research team since day one. There were two- major incidents. The company was founded in 2020, but we really got funded and started in 2020, end of 2021, beginning of 2022 Two things happened in 2020. There were two major events. One was there was a sup- both related to supply chain. So one was Log4j.
Zaid: There was this very common package that everybody used that had this crazy [00:27:00] vulnerability that hackers can exploit with push button ease, right? And so the whole industry tried to find where are we using this? We gotta fix it. Like it was, if you don't fix it quickly, assume hacked, right?
Zaid: And that was one, and the second thing was there was a very famous supply chain incident called s- for a company, affecting a company called SolarWinds in the US. Now, both of these were Richter scale nine type of events. The whole industry kinda wanted... woke up. And we started, we focused our research on supply chain industry as early as then.
Zaid: And we're very proud of the work that the team has done. So they, we've produced the world's, first attack models, so like actually modeling out the theory how attackers can actually hack developer infrastructure we've released a number of open source tools that we've actually learned that some of the biggest security companies in the world use internally to to test their stuff, and some of the biggest consulting shops.
Zaid: We even found out that Google actually uses it in-house. Incidentally, all these tools have a Montreal food name [00:28:00] theme. So one's called Poutine, one's called Bagel, one's called Smoked Meat. That's the three open source tools that we're very proud of. And so yeah we just believed in, in security research.
Zaid: It's... I think also good security companies have that function. This is where I always say research informs product decision, right? It's-- We're kinda s- sitting at the forefront of what is possible, how do hackers think, what can they do, and then you work your way backwards from there. How can you secure, how can you protect and so on and so forth.
Zaid: Now th- this is the origin of how that came to be. Now, how do we actually end up helping customers is multiple ways. So again, the mission didn't change. It-- We're about we wanna help companies build software securely and build secure software. Five years ago, that was DevOps and DevSecOps and shifting left, and basically just, developers are shipping code 30 times a day.
Zaid: Can we scan 30 times a day and tell the developers what to fix, what's worth fixing, and so on and so forth? Now we've got agents writing code, and then we've got all these attackers coming in through open [00:29:00] source land. These are the two biggest risks. So our technologies, our products really try to address these two areas.
Zaid: We went into the developer machine because that's where Claude is working. That's where agentic-- where the agents are generating code. So you have to be, like, right there before the code is even written, you have to be telling Claude how to write code securely. Before Claude decides to bring in a library or a package, you have to tell Claude, "Let me first check if this is safe to bring and use, or if there's known malware or any weird signals, or if there's something better to use."
Zaid: Once code gets written, you wanna do... There's a whole slew of checks that you gotta do. And then, of course, we wanna look at the machine and say, "Okay, why is this developer leaving these 30 credentials open? If they were to fall victim to a supply chain attack, the damage would be big. Let's tell the developer how to fix and improve the, the machine posture," and so on and so forth.
Zaid: Now, once code gets generated and gets pushed to your usual CI/CD pipeline We have the same type of engine, the same agentic, the same agents working with cutting-edge scanning [00:30:00] technology some of which we built, some of which we acquired to try to give the same level of comfort and guarantees to the organization, right?
Zaid: Yeah. Where the code gets generated, whether it's human written or agent written, doesn't matter at the point of inception all the way through to production, we're there.
Nectar: How do you think about the, the classic investor question of TAM, right? Because like you mentioned, some of the biggest software companies in the world are using your product today.
Nectar: I know. But as every, as software goes, trends to zero and every company becomes like software, there are many more at least software companies. Is that the TAM? Every company in the world is over time? Or do you think about it more niche? It has to be enterprise, bigger, like multiple devs?
Zaid: No, I think it's... it, so for sure the market today is very much enterprise. The companies that actually spend serious amounts of money on producing secure software typically tends to be large enterprises. There are historic- historical reasons for that. Usually, it's like regulatory. Th- there were...
Zaid: If you're t- if you're a financial services company, you're expected, to [00:31:00] comply with certain regulations that basically say you can't just whip out software, throw it over the fence if it handles client financial information. Sure. You have to show that you're doing work to make sure that software cannot be breached easily, right?
Zaid: Same thing for healthcare and so on and so forth. So it typically tends to be enterprise. Of course, how the world evolves, especially with things like, models getting really good at breaches, at hacking, I think the market's always expanding. It's never gonna shrink. In fact, one of the things, when Mythos news came out, it was a double-edged sword.
Zaid: I think the... On one hand some voices said, "Oh, this is the end of AppSec. The models are now gonna take over. They know how to write code. They'll know how to write... They know how to hack code, so they'll be the best at telling you how to fix code." And so that was, one suite of voices.
Zaid: The other suite of voices were basically saying, "Look, the model that wrote the code can't be the model that secures the code." It, it's trained a certain way, so you need a different model to be able to- [00:32:00]
Nectar: Yeah, I was gonna- ...to do it, actually, on Mythos, right? Yeah. We were talking about how I th- think it's a good thing is it put a lot of emphasis.
Nectar: Yes,
Zaid: it does.
Nectar: What is Mythos actually really good at when it comes to cybersec, and where is it overhyped? You mentioned a little bit of it, but maybe to double-click on it.
Zaid: Yeah. Look, so we don't have access... Very few companies have access to Mythos, but you can go with what some of the companies that have done their testing, and they have compared Mythos and some are very public case studies Mythos or ChatGPT-55 cyber capabilities, I think it's undoubtedly, like at this point it's a fact that Mythos and Mythos-like models are very good at let's look at the source code, let's find a bunch of like small things that a human will find very difficult to actually chain together into an exploit and create a working exploit.
Zaid: I think this is a given at this point. This is a good innovation, it's a good technology, and it certainly will have its place. Now, writing software is complex. This class of things that Mythos and Mythos-like technologies can find and prove exploitability is a fraction [00:33:00] of everything that has to go into producing secure software.
Zaid: Like everything we talked about the developer supply chain, for example-
Nectar: Yeah ...
Zaid: threat, that, that's not something Mythos is involved in, now I do think it's-- what I tell customers is like Mythos is, and Mythos-like models are part of the story, and they should be part of everybody's story.
Zaid: They really should. No vendor should be making a claim that, "Look, we built a better version of that, and you should, you should use our niche." I think that's that's a difficult argument to, to make. But at the same time, Mythos is extremely expensive. So if-- I'll give you an example. Recently, one of our customers went from 15,000 pull requests a month to 30,000 in the last three months.
Zaid: So they doubled the amount of code they're producing, give or take just because they switched to a different org structure with more agents writing code. The estimate for running Mythos on every single one of these is in the millions of dollars, like tens of millions, in fact, right? 'Cause it costs [00:34:00] money to run this model that runs for hours consuming huge code bases.
Zaid: So it's kinda not something you wanna be running every day on every line of code generated by an agent. At least not for the foreseeable future, right? So the question isn't is Mythos great tech? Yes, of course it is. The question is how do we best use it in addition to everything else that- Yeah.
Nectar: Yeah, no, that makes sense. It's a very eloquent way the first time I hear that framing. If you go back to Boost and like- Yeah ... we talked about, all the different opportunities because of just the market timing, right? Yeah. You guys are sitting at the right place at the right time.
Nectar: Going back to why I'm biased and bullish- Yeah ... what's for you the most exciting thing right now, right? For the prospects of Boost now that you've closed your round, you guys are moving forward. What are you excited about?
Zaid: I think a lot of things excite us.
Zaid: Really, I think, so the first, the, I think-- So we touched upon Mythos. I think there's, So one of the things that we're hearing a lot now is, for better or worse, and I do think it's for better the threat of AI models making [00:35:00] exploitation very quick is forcing companies to rethink, "All right, we gotta up our game very quickly."
Zaid: And so there's this broad level approval, if you will, to all right, we gotta get quote-unquote Mythos ready, right? So we need to make sure that in a few months when this technology is accessible to bad actors that it's not point and click easy for them to get in. So there's this like big mandate.
Zaid: What does it take? So there's an area for innovation. There's an area we've been in, been doing a lot. The developer endpoint stuff is we're seeing a lot of traction. It's a top concern. We're talking to CISOs. They're telling us like, "Everybody in my company's coding. I have no idea what they're downloading, what they're using, how they're doing it.
Zaid: I need to just understand what's there first and then start securing stuff." So that area also I think is very promising. The last area that we are also, I think we're quite differentiated in, is the area [00:36:00] of CICD security. W- we talked about supply chain attacks. It's mostly one model.
Zaid: You use open source packages, some hacker poisons one, you use it, you get affected, you lose your credentials, now they can impersonate you and do things like that. There's many other flavors of supply chain attacks, one of which is, when companies think of their The software that they build, they think of the main application, the main app that they build.
Zaid: That's what they... But they don't realize is it's actually apps that you use to build those apps, the s- CI/CD pipelines. And they have their own technologies and, the common one would be GitHub Workflows and GitHub Actions, and things like that. But there's code there. It's instructions on how to take a developer input and test it, and if the tests pass, build this artifact, and if it works, push it to production and do things like that.
Zaid: And it turns out that these can be hacked too. So these are just software, and all software can be bypassed, unless you put a lot of effort into it. And we're kinda considered experts in that area. In fact, all... not all, but a couple of the tools that, the open source tools that I mentioned are ki- like [00:37:00] specialized for that area.
Zaid: And hackers are picking up, like they're starting to abuse these types of attack surfaces. In fact, like I said, some of the biggest software companies in the world, they trust us to continuously, help them find and fix and address these types of security issues. So there's no shortage. Like I said, the technology's, technology landscape is changing so fast, and much faster than security research can keep up.
Zaid: And as a result the industry is required to step up and find innovative answers to these problems.
Nectar: Yeah.
Nectar: F- I could go on for a while, man, with Boost, but maybe I wanna on one last topic- Yeah, sure ... I wanna geek out on with you is you mentioned agile development and it's like it feels like agile's no longer- Oh, it's no longer, yeah
Nectar: that relevant. Yeah, correct. It's like it's... and we, I know you've spoken with Fred a little bit about this whole brave new world of how you create software. So I wanna selfishly pick your brain on how do you think about structuring your team, right? And now obviously with Boost you have this blank slate of creating a new- Sure
Nectar: team. How should [00:38:00] founders think about building software teams today?
Zaid: Yeah, for sure. It's a great question, timely question. I've talked to many, not only founders, even large companies, even some huge airline companies are doing what, I'm about to talk about, which is, for the last, I don't know, maybe 10, 15 years, Best performing engineering teams were generally structured like a functional pyramid.
Zaid: You'd have a, an engineering head and then a number of directors or managers, and then, you go down to like basically these two pizza teams, so eight to 12 people. And they own a project. They do these two-week sprints, give or take. If you're really fancy, you're doing one-week sprints.
Zaid: But it was the agile DevOps ship quick, ship fast da. Of course, this was before agents did a lot of work. We didn't have coding agents. So the industry woke up and said, "Okay how do we write software in a day and age where agents should be able to write a lot of..." What's the right team size?
Zaid: What's the right team structure, and so where, I, I'm-- where I'm [00:39:00] seeing a lot of convergence is those two, the, those eight to 12-person teams are too big, okay? It was general consensus because the assumption is like a good developer should be-- who's good with AI and coding agents should be able to drive, I don't know, two to five agents like continuously.
Zaid: You have some outliers that basically build systems of agents that prompt agents and work with, you know. But for the vast majority of, I think, the industry it's really this like one engineer's got three to five agents working at any one point in time. And so a team of three to four Engineers working closely on a comp- on a particular project with good use of AI should be able to do the work of what used to be 10, 12 people before, right?
Zaid: So that's where they start with. Why three, four? Why not eight? Because it-- communication overhead becomes a big thing. The dynamics change. It used to be that we needed two-week sprints, maybe a bit, and then we'll do a day of planning to fill up work because the bottleneck was we still need time to write the [00:40:00] code.
Zaid: Now in-- for-- you talk to many organizations that are restructured, they're like we plan the sprint in a day and a half. The work is done in a day and a half." It, it makes no sense anymore to start doing the same old structure. So everything's being flipped upside down. I've, I talked to high-performing organizations considered some of the best engineers on the planet, right?
Zaid: And they're restructured into three-person teams. There's no sprints. It's, "Here's our objectives for the quarter." These small pods are empowered and autonomous, and you work with, very closely with a product organization, product owner. There's no silos. There's no, go up the f- the communication chain and then down again.
Zaid: It's a lot about recognizing that the bottleneck is no longer writing code. It's about how fast you can learn, how fast you can respond to customer requests, market feedback, and so on and so forth, and it changes everything.
Nectar: Yeah.
Zaid: Yeah.
Nectar: Does the software team sit somewhere different? Do they need [00:41:00] to be a silo anymore?
Nectar: Like-
Zaid: I don't, I-- So I don't think they're a silo. I can tell you, I, I'm not gonna mention the name, but like a large airline company that we work with they have at this point, and this is like a 50-plus-year-old company, 600 developers in the last year. They, and they used to have the traditional structure, and now it's 200 three-person teams.
Zaid: So completely like autonomous, right? And they each own a small portion of the product, and they're expected to be autonomous and find information where they need to. It's not really... I think they still report to an engineering head just because of the size. But practically speaking, it's no longer centered around a functional center of excellence.
Zaid: Okay, we need to centralize engineering practices to make sure that we're doing s- things that are, consistent across the board. There's always gonna be an element of that, but it's more let's organize for performance. What is the [00:42:00] thing that will-- What is the organizational structure and body of knowledge and practice and culture that gives us maximum output?
Zaid: This is what everybody's organizing because the assumption is the companies that figure that out sooner are just gonna have such an advantage in ability to innovate that you have no choice. You have to get good at it quick or become so slow that ir- you become irrelevant.
Nectar: Yeah. Yeah. It feels like the, the the Red Queen effect, right?
Nectar: Yes. It's it's like totally the case
Zaid: today. It's
Nectar: in play, yep. The faster you run, the faster you stay in place a little bit. Yeah. But there's a few people that are able to break out, right?
Zaid: Correct.
Nectar: Yeah. Zayd, I think I could bug you for a lot more. Maybe a final question. Sure. Like lessons learned from your first company that you're now porting over to Boost, right?
Nectar: Any any founder lessons and some of the scar tissue that you've, Of course ... that you've brought.
Zaid: Yeah. There's, honestly, too many to count. I think for the first one I very much did, textbook first-time founder scars. So if you build it, they will come. Tech is more important than figuring [00:43:00] out go-to-market.
Zaid: Those were the two biggest ones. And we kinda in, at Boost Security, we started off with we're basically we're working with customers from day one. Six months after we... I wrote the prototype myself, me and my co-founder. And six months prototype, it was already in production live at one customer.
Zaid: In three, four months after, it was at six companies. Then we started the journey. So it was really work closely with with clients from the beginning, trying to figure out go-to-market early on. I do think that it's, even though there's scar tissues, lessons learned but the times are also different, so it's back then Cyber was still early, it was easier to, to s-stand out. Now there's just a lot of cyber companies in general, and there's a lot of companies that are really good at marketing, not so much at tech, but, you have to compete with them. Again, the agents are kinda like, the whole agentic technology is changing everything as well.
Zaid: So a lot of the lessons can be ported over, but you're really... I think what's more [00:44:00] important is the skill, because you have to adapt. The conditions are not gonna be the same, regardless of what lessons you can port over with you.
Nectar: Yeah.
Nectar: Zayd, really appreciate your time today. Oh,
Zaid: pleasure.
Zaid: Thank you for having me.
Nectar: Final question- Yeah ... would be just if people wanna reach out, learn more about Boost and follow the journey or connect- Yeah ... with you.
Zaid: Yeah, for sure. So boostsecurity.io is the company. If you're more interested on the security side less commercial, more interesting research, you can find everything on labs.boostsecurity.io.
Zaid: Me on LinkedIn, Zayd Al Hamami, or, very easy to find me, Z-Zayd. Not many people with that name in cybersecurity with, association to Boost Security,
Nectar: awesome. Thank you so much, man.
Zaid: Thank you.
