Monday, April 24, 2017

Week 13: The Entrepreneurial Journey

As we reach week 13, we near the end of this class. I am grateful to have been assigned to the group I was assigned to. You see, we were all the leftovers, all the stragglers who were unable to find groups in earlier weeks. We get things done, and we get things done fast. Having such an efficient group made the project entirely more enjoyable to work on.

Nevertheless, being in a group of 4 women and 1 man, all Asians in some form or fashion--I cannot help but to express my ire at the manner in which groups were formed. I have made token protests and suggestions in the very beginning; that is, I firmly believe that randomizing groups would have been a much more efficient way to achieve diversity. Instead, most of the groups seem to be entirely made up of one ethnicity, with perhaps a token minority (whether race or gender) here and there. Perhaps being in a diverse group would have made for a more enriching classroom experience; perhaps not. I understand though, that in the real world, in the land of start-ups, the founding teams often come from very different backgrounds. Certainly, with my group, we had our mix of international students and varied nationalities within Asian countries. But I imagine there would have been a lot more to experience with a more diverse group. 

Given that my group lucked out on the work ethics side of things, there was no actual difficulty once the ball got rolling on our project. We decided upon our patent rather quickly, although there was the setback of being unable to contact the inventors. we did additional research into the patent and its applications in an effort to make up for this, and to our luck, the inventors left behind several technical papers explaining it. Admittedly, we also left a lot of details ambiguous until we were forced to hammer them out for our final pitch. For several weeks, we were unable to decide upon how to implement our patent--we knew it would be technical, and that our company would follow the SaaS model, but how would our MVP look, and how would our pricing model work?

We discussed several possible routes we could have taken with the product. We considered making it an app, or a plug-in, and finally decided to just sell it as a software. Suffice to say, we pivoted a lot, particularly regarding our target customers. We had relatively little difficulty in getting our customer interviews, but a lot in hammering out specifics. Ultimately, we decided to target mid-sized companies (100-5000 employees), whether they were mature start-ups or recently exited businesses, because such companies had shorter sale cycles. Our product, being a safety feature, needed to establish a heavy base of trust, and we felt that these were our best targets. Smaller companies would not be able to afford us, and larger companies would have taken too long, being wrapped up in bureaucracy as they were. What is left is to really convey this idea to the investors, and whoever else is listening to our final pitch. 

I will admit to a little anxiety regarding the pitch, because some of my group have less confidence when it comes to speaking, and it shows. Our more technologically minded people had issues explaining the patent in a manner that makes sense to the non-technically minded, for instance. As a team, we have given each other feedback, so we have tried our best to overcome this barrier. We hope to be fully ready for the final.

Thursday, April 20, 2017

Week 12: Sprinting to the Finish Line

My group met yesterday to finally put together our pitch deck. Before, we had all the information and research about our product that we wanted and needed to say, but we had not really put something solid together. Yesterday, we really spruced up our deck and branded our product--logos and colors and all. I am extremely excited to go about actually pitching this, because we put a lot of work into it. 

We also hammered out some details that were murky in the past, and bolstered some ambiguous phrases with images and words.

Fauzi did a particularly great job on the logo and other assets we used. 

Thursday, April 13, 2017

Week 11: Business Strategy and Market Size


There has been some ambiguity over the last few weeks regarding how our group was actually planning to implement ORAM, and which market we were planning to target first. After doing ample research on potential competitors (other cyber security or cloud security related companies), we have decided to sell in two phases. 

It is important for our product to create a brand based off of trust. To achieve such purposes, it does not make sense to immediately target large companies such as Intel or Costco, because the sales cycle is so much longer. Our aim is to target mid-sized companies, or companies with 100-5000 employees, in the beginning. Additional research has shown that the companies that have spent the most on security measures in the last few years include those in the financial and technology sectors. To get these companies to use our product, we are willing to extend a 30-day free trial. Understandably, there are costs associated with providing the service for free, but this will ultimately pay off once 1. the companies realize that we are saving them on costs and will therefor pay for our product ($5 per headcount) and 2. these companies might acquiesce to a case study or our usage of their logo on our website. 

Once our product has amassed an ample amount of case studies and logos, then we are positioned to reach out to larger companies (those with headcounts over 5000). We have references to draw back on--and ideally, many of these mid-sized companies will have names that are relatively well known--which provides us an image of authenticity. Our eventual plan, of course, is to take over the world.

We have also conducted a formal TAM, SAM, SOM analysis during our meeting this week. Our meeting concluded with an ice cream party (we worked on our presentation for almost three hours, so we felt it was justified).


TAM: the amount companies are currently spending on information security and on cloud services.
  • We estimate our TAM to be around $300B based off of current estimates of the cloud and security market, and projected growth potential.

SAM: mature startups and mid-sized companies (100-5000 employees) who spend money on cloud security services.
  • The Sans Analyst Program found that mid-sized companies budgeted $1M on average during FY 2015 to security. It projected that these companies would budget $1M-$10M during FY 2016. Larger companies (over 5000 employees) budgeted $1M-$10M in FY 2015 and were projected to budget $10M-$50M in FY 2016.
  • Geographically speaking, there are 30 million SME in the USA. 93% of businesses use the cloud in some fashion. We assume 1% of the SME businesses are relevant, and calculate SAM as follows: 30M * 0.93 * 0.01 =  279000 companies to target
  • Say these companies have 100-5000 employees, paying $10 per employee.
  • 279000 * $10 * 2000 employees = $5.58B is our SAM


SOM: we estimated this to be around 6% of our SAM.
  • Following a similar revenue model as SOPHOS (security software and hardware company)
    • → projected $250K in Year 1
    • Expected sale of 50,000 units at $5 per unit
  • $300M by Year 5

Tuesday, April 4, 2017

Week 10: Patent Analysis and Venture Dojo Feedback

Our group plans to present on a startup based off the ORAM patent.

Companies and individuals have attempted to create something similar to the method described in the patent linked above, with limited success. Previous attempts have required either too much data to conceal a single megabyte of data, or taken too much time, thereby being too cumbersome to commercialize. The Berkeley patent proposes a method that would be 63 times faster than existing methods. The patent would conceal access patterns to data storage in the cloud. It would partition server data into smaller electronic data storage partitions and shuffle these blocks randomly, thereby making it difficult for attackers to extract data based off of access patterns.

The patent has 21 claims. Claim 1 explains that the patent is claiming the method of concealing access patterns to electronic data storage, where data storage is partitioned into blocks of some size, and then randomly rearranged. Claims 2-19 go into further detail over how data is stored and where, and how data is compressed and the ORAM process is applied. Claim 20 and 21 are alternatives of Claim 1, in the sense that they are still describing the method to conceal access patterns to the cloud, but in different kinds of servers and with different existing encryption services.

The patent would have a huge business potential, facing a several billion TAM. According to various customer interviews that we have conducted, companies are already pouring millions into in-house cloud security solutions, and many would be willing to outsource to a third party for lower costs. One company in particular is spending roughly $120k+ on each employee in a 30+ people IT security team, and given that ORAM could be made to service all kinds of companies--retail, technology, internet, large, mid-size, small--the potential market is huge.

--

Venture Dojo Feedback:

1. The videos are very helpful--concise, and with nice diagrams and slides to help visualize.
2. I dislike how it forcibly created a profile for me with a blown-up version of my Google Account profile picture. I cannot change it and do not want my name on that site.\