
Product-Market Fit for Cybersecurity: How Founders Did It
July 27, 2026
TL;DR: Product-market fit for cybersecurity means earning trust in a market where products are binary — they either work or they don't. Based on 200+ founder interviews on the PMF Show, expect 6-9 month enterprise sales cycles and failed POCs first; then growth compounds: Wiz hit $100M ARR in 18 months, and Axonius went $1M to $100M in 4.5 years.
After interviewing 200+ founders on the PMF Show, a clear pattern emerges: product-market fit for cybersecurity follows different rules than the rest of SaaS. Security founders sell to skeptical CISOs, survive multi-year enterprise sales cycles, and face a pass/fail product bar — yet the category consistently produces some of the fastest-growing companies in software. This post breaks down how the founders of Wiz, Doppel, Illumio, eSentire, Axonius, and Huntress actually found PMF in security, with the numbers, timelines, and direct quotes from their episodes.
Why is product-market fit different in cybersecurity?
In most SaaS categories, a product that solves 70% of the problem can still win deals. Security doesn't work that way. According to Dean Sysman, CEO of Axonius, who took his company from zero to $100M ARR in roughly five and a half years, the bar is absolute:
"In cybersecurity products are really black or white. It's not like the product works fifty percent and somebody will buy it for fifty percent of the cost. It's either it works or it doesn't." — Dean Sysman, Axonius
That binary bar shaped Axonius's early journey. After raising a $4 million first round, Sysman ran many POCs that failed outright before landing a first paying customer — a deal he priced by asking the buyer what a full-time employee doing the same manual work would cost, landing a high-five-figure annual subscription. As shared on the PMF Show, that same deal size would be six figures for Axonius today.
The compensating advantage is budget resilience. According to Kevin Tian, CEO of Doppel, security spend survives every market cycle:
"Cyber never goes away. Bear market, bull market." — Kevin Tian, Doppel
That combination — a brutal product bar plus durable demand — is why cybersecurity PMF is slower to earn but more valuable once won.
Key stat: Axonius failed multiple POCs before its first paying customer, then went from zero to $1M ARR in under a year once messaging and time-to-value clicked.
How long do cybersecurity sales cycles really take?
Longer than almost any other category — especially before you have a brand. Andrew Rubin, CEO of Illumio, spent roughly two years in stealth meeting the biggest banks in the world before his company sold anything. Illumio raised over $40 million in its first six to seven months with a team of fewer than 20 people, then raised a $100 million round almost exactly when revenue started two years later.
Asked on the PMF Show how long it took to close early customers like Morgan Stanley — which became a seven-figure deployment — Rubin was blunt:
"It was a multi-year sales process because it's not like it started the day we came out of stealth." — Andrew Rubin, Illumio
Even at maturity, the cycles stay long. According to Rubin, a typical enterprise security sales cycle today runs "call it, six to nine months. Maybe it's 12 based on procurement" — and that's with brand, referrals, and references. As a startup, he told Pablo, "You got nothing."
That timeline math is why Rubin argues capitalization is part of PMF strategy in security:
"The difference between being very, very, very, very early in something and being too early in something... It's really only one word. And the word is actually not time, it's bankruptcy." — Andrew Rubin, Illumio
If your buyer takes 12 months to sign and your runway is 14, you don't have a sales problem — you have an existential one.
Key stat: Illumio raised $40M+ in its first seven months and still needed a multi-year sales process to land its first enterprise security customers.
How do security founders earn a CISO's trust before they have a brand?
Trust is the actual product in early-stage security. Eldon Sprickerhoff, founder of eSentire, took seven years to reach $1 million in ARR — and what carried the company through was a small group of early clients who acted as evangelists, references, and door-openers. According to Sprickerhoff, those "true believers" bent over backwards to support the company, and the obligation ran both ways:
"I did not want to let them down, because they put their reputations on the line and their own jobs on the line to help me succeed." — Eldon Sprickerhoff, eSentire
That's the CISO trust equation in one line: a security buyer who champions a startup is betting their own career on it. eSentire repaid the bet by making clients look good where it mattered most — "We made them look so good when it came to audit time that they just wanted to be part of that journey," Sprickerhoff shared on the PMF Show. The payoff came late but steep: after seven years to $1M ARR, eSentire went from $1M to $10M in just three years.
Dean Sysman of Axonius adds two tactical rules for the same buyer. First, "never call anybody's baby ugly" — pointing out gaps in a CISO's architecture makes them defensive, so frame findings as wins for them. Second, compress time to value. Sysman recalled a public-company CISO who was asked which security products he loved most and named Wiz and Axonius, because with both, "time to value was almost immediate. I had spent very little effort to see an immense amount of value."
Key stat: eSentire took 7 years to hit $1M ARR, then 10x'd to $10M in the following 3 years on the strength of reference customers.
Can you pivot your way into cybersecurity product-market fit?
Doppel did exactly that. Kevin Tian and his co-founder started in early 2022 protecting NFT marketplaces from fake tokens, backed by a $400K pre-seed from South Park Commons. Their first contract — $5K per month — was signed before the product was even built. A $5 million seed followed in summer 2022. But by 2023, the founders noticed the pull was coming from somewhere unexpected:
"We quickly realized that a lot of the people who were really pulling for Doppel and really willing to spend a lot of money on Doppel were the cybersecurity folks." — Kevin Tian, Doppel
The impersonation problem Doppel solved for crypto — phishing sites, fake social accounts, social engineering — existed at every company in the world, and it was security teams, not trust-and-safety or legal teams, who had the budget and urgency. So at low seven figures in ARR, Tian made the call: shut down the original API, pull in dark web threat intelligence, and reposition the product for CISOs. Doppel 10x'd its revenue that year, closed an $18 million Series A led by Andreessen Horowitz at the end of 2023 — mid-pivot — and has raised over $120 million in its first four years.
According to Tian, the lesson is that PMF in security is never a single moment:
Never miss a founder's PMF story
Subscribe to The PMF Show"Product market fit's not a one moment thing... We got initial product market fit with our first products. We pivoted, right? And then it had to go get product market fit with our other products." — Kevin Tian, Doppel
Key stat: Doppel pivoted to cybersecurity at low seven figures in ARR, 10x'd revenue that year, and raised $120M+ within four years of founding.
Do you need to sell to enterprises to find PMF in security?
No — but the wedge changes everything. Kyle Hanslovan, CEO of Huntress, left the NSA and built threat detection for the small businesses everyone else ignored. His first five or six discovery calls to local law firms and CPA shops were humbling — the people answering the phone had no IT department at all. Investors were equally unconvinced: when Huntress went out to raise a Series A with over 90% renewal rates, Hanslovan got more than 60 rejections.
"Turns out, even though we had conviction and felt we had data, nobody else agreed. I was told no by everybody. 60 plus no's." — Kyle Hanslovan, Huntress
He bridged with his most loyal angels instead — and, as shared on the PMF Show, that 2018 bridge round returned roughly 140x by 2024. The numbers vindicated the SMB thesis fast: Huntress went from $1.5 million to $5.3 million in ARR in 12 months, and term sheets jumped from valuing the company at $3 million to $30-50 million. Today Huntress protects 150,000 customers, largely through a network of 5,000+ MSP partners, and passed $100 million in revenue.
The Huntress playbook is the counter-example to Illumio's: instead of two years of stealth and seven-figure bank deals, a high-volume, partner-led motion with fast time to value for buyers no one else served. Both found product-market fit in cybersecurity — through opposite wedges.
Key stat: Huntress grew from $1.5M to $5.3M ARR in 12 months after 60+ VC rejections, and now protects 150,000 customers.
What does hypergrowth look like once a security company hits PMF?
Wiz is the benchmark. Founded in 2020, Wiz hit $100 million in ARR in 18 months — at the time, the fastest in software history — and within four years was in talks to be acquired by Google for $23 billion, roughly a 40x revenue multiple on about half a billion dollars of ARR. For comparison, Microsoft trades around 15x revenue and Google and Meta around 5-10x. Pablo's breakdown on the PMF Show's Wiz episode credits three things: insane growth, an insane (four-time repeat) founding team, and insane discipline.
Competitors noticed the same thing. According to Dean Sysman of Axonius, Wiz turned even fundraising into a growth channel:
"They use their fundraising as a brand tool... they kept raising many, many different rounds. Kept raising their valuation and that's a very dangerous game by the way. But for them, they were able to pull it off very effectively and people kept hearing about them." — Dean Sysman, Axonius
Sysman also emphasized that Wiz engineered its product around what would make users tell other users to try it — deliberate word of mouth in a category that isn't naturally viral. Axonius itself shows the repeatable shape of post-PMF security growth: zero to $1M ARR in under a year, $1M to $10M in about 18 months, and $1M to $100M in four and a half years — among the fastest ever in cybersecurity. In this category, PMF arrives slowly and then compounds violently.
Key stat: Wiz reached $100M ARR in 18 months and a $23B acquisition offer at a ~40x revenue multiple within four years of founding.
Key Takeaways: Finding Product-Market Fit in Cybersecurity
1. Security products are pass/fail. As Dean Sysman of Axonius put it, cybersecurity products are "black or white" — nobody buys a product that half-works, so expect failed POCs before your first win. 2. Budget your runway against the sales cycle. Enterprise security cycles run 6-9 months with a brand and multi-year without one; Andrew Rubin's warning is that "too early" really means bankruptcy. 3. Your first customers are betting their careers on you. eSentire's true believers put "their reputations on the line" — repay them with references, audit wins, and white-glove support. 4. Time to value is the trust shortcut. The reason a CISO named Wiz and Axonius his favorite products: near-immediate value for minimal effort. 5. Follow the buyer who pulls hardest. Doppel found PMF by noticing that cybersecurity teams — not its original trust-and-safety buyers — were the ones willing to spend, and 10x'd revenue the year it pivoted. 6. The enterprise is not the only wedge. Huntress built a $100M+ revenue security company on SMBs and 5,000+ MSP partners after 60+ investors said no. 7. PMF in security compounds late but fast. eSentire took 7 years to $1M and 3 to $10M; Axonius went $1M to $100M in 4.5 years; Wiz hit $100M ARR in 18 months.
FAQ: Common Questions About Cybersecurity PMF
Q: How is product-market fit for cybersecurity different from regular SaaS?
A: The product bar is binary — security tools either work or they don't, so partial solutions don't sell at a discount. Buyers (usually CISOs) risk their jobs on vendor choices, which makes trust, references, and time to value the core of PMF. Sales cycles are also longer: 6-9 months for established vendors and often multi-year for unknown startups, based on Illumio's experience on the PMF Show.
Q: How long does it take a cybersecurity startup to reach $1M ARR?
A: The range is wide. Axonius did it in under a year after its first customer, Doppel crossed seven figures within roughly two years, while eSentire took seven years. The more consistent pattern across 200+ PMF Show interviews is what happens next: once trust and messaging click, $1M to $10M often takes only 18 months to 3 years.
Q: How do you sell a security product to CISOs as an unknown startup?
A: Use network selling — warm intros through past colleagues, investors, and existing customers — and design POCs that show value almost immediately. Never make the buyer look bad: Axonius's rule is "never call anybody's baby ugly" when you find gaps in their environment. Early champions will act as references if you make them look good at audit time, as eSentire's Eldon Sprickerhoff described.
Q: Why do cybersecurity startups grow so fast after finding PMF?
A: Security budgets persist through bear and bull markets — as Doppel's Kevin Tian says, "cyber never goes away" — and a working product spreads through the tight-knit CISO community. That's how Wiz reached $100M ARR in 18 months and Axonius went from $1M to $100M in 4.5 years.
Sources: Listen to the Full Founder Stories
- Wiz (Season 3) — Pablo's breakdown of how Wiz hit $100M ARR in 18 months and drew a $23B acquisition at a 40x revenue multiple.
- Kevin Tian, Doppel (Season 5) — pivoting from NFT protection to social engineering defense, 10x-ing revenue, and raising $120M+ in four years.
- Andrew Rubin, Illumio (Season 4) — two years of stealth, $40M+ raised in seven months, and surviving multi-year enterprise security sales cycles.
- Eldon Sprickerhoff, eSentire (Season 4) — seven years to $1M ARR, three years to $10M, and the true believers who made it possible.
- Dean Sysman, Axonius (Season 4) — failed POCs, pricing a new category, and one of the fastest $1M-to-$100M runs in cybersecurity.
- Kyle Hanslovan, Huntress (Season 3) — from the NSA to 150,000 SMB customers, 60+ VC rejections, and a 140x bridge round.
Last updated: July 2026
Want more founder stories like this?
Subscribe to The Product Market Fit Show for weekly episodes.
Subscribe Now