The Business of Cyber Security

Time-to-Trust and First Customers

Ent emerged from stealth on June 16, 2026 with a $100M seed round, one of the largest in cybersecurity history. Its founders were Elias Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and part of the team behind Microsoft Security Copilot. The round was led by Decibel with Sequoia, Crosspoint, Craft, Shield Capital, Felicis, and In-Q-Tel. The size of a seed round for founders with that track record reflects a structural feature of security venture: the founders had addressed the hardest non-technical problem a security startup faces — time-to-trust — before the company existed, because a CISO will take a meeting with the people who built Security Copilot. That borrowed credibility can matter more than any feature.

What time-to-trust is

In most software categories the buyer asks "does it work and is it worth the price?" In security the buyer asks a prior question: "if I deploy this and it fails, do I get fired — or breached?" The product is bought to prevent a low-probability, high-consequence event, and it sits in the critical path of the enterprise (the endpoint, the identity plane, the network). A bad SaaS tool wastes money; a bad security tool can take down production or miss the breach it was bought to stop. So the buyer underwrites the vendor, not just the software: the founders' pedigree, the board, the existing customer references, the funding runway (will they exist in three years?), and the proof that someone like them has already bet their job on it.

Time-to-trust is the elapsed time from first contact to the point where a reference-able buyer will deploy in production and say so publicly. It is the security-specific form of the cold-start problem: a seed-stage company with a working product can still take 12–18 months to convert its first true enterprise reference, because trust is earned in a sequence that capital cannot shortcut — only compress. Under-capitalized startups often fail in this gap, running out of runway before the references compound. That is why security is a capital-intensive seed market (see the Israeli foundry, where the model is engineered specifically to pre-load trust).

How startups compress it

The winners do not wait for trust; they manufacture it in a deliberate order. Each step lowers the perceived risk for the next, more skeptical buyer.

Lever What it does Why it compresses trust
Founder pedigree Ex-operator, ex-Unit-8200, prior exit, recognized researcher The buyer transfers trust from the person to the product (Ent, Wiz, Abnormal)
Design partners (first 5–10 CISOs) Co-build with friendly buyers who shape the roadmap Converts cold buyers into co-authors; produces the first references
A specialist VC's Rolodex The fund's first-ten-CISO introductions Skips months of cold outreach; the VC's name vouches for the founder (see 07a)
Third-party validation MITRE ATT&CK evals, Gartner mentions, analyst coverage, certifications Independent proof the buyer can cite internally to defend the choice
Public reference logos + case studies Named customers willing to be quoted Each logo de-risks the next buyer; the flywheel starts
Community / researcher credibility Open-source tools, threat research, conference talks Builds bottoms-up trust among practitioners before the CISO is asked
Capital as a signal A large, named round Answers "will you exist in three years?" — Ent's $100M seed is a trust instrument

The deepest moat is the reference flywheel: the first reference is the hardest and slowest; each subsequent one is faster because the buyer can point to a peer. A company that reaches ~10 enterprise references in a tight vertical has effectively crossed the chasm — its time-to-trust for the next buyer in that segment collapses from months to weeks.

These levers compress time-to-trust; they do not settle whether the thing is a company or a feature. Borrowed founder credibility and a large, named round buy the first meeting and the runway to the first reference — but a platform can lend the same trust to its own bundled version, and a CISO who trusts the founder will still not pay standalone for what the incumbent now ships inside a tool already owned. An outsized seed (Ent's $100M) also raises the bar it is meant to clear: the mark must be justified against a category and a moat, not a résumé. Time-to-trust is a barrier to entry that protects the startup, but it is not the moat — category position and the durable-moat test still decide feature-versus-company.

The reference flywheel: time-to-trust collapses as logos compound Months to convert the Nth enterprise reference (illustrative) 6mo 12mo 18mo 1st 2nd 3rd 5th 10th 20th+ ← the "trust chasm": ~10 references and the cycle is weeks, not months Illustrative model based on enterprise security GTM patterns (design-partner → reference flywheel). Exhibit: The Business of Cyber Security.
Capital cannot skip the first reference — it can only fund the runway to reach it. The asset being built is not the product; it is the reference base. That base is also the most durable thing an acquirer pays for.

Relevance to M&A

Time-to-trust reframes what a strategic acquirer is buying. In a sub-scale security deal the headline is the technology, but the durable asset is frequently the installed reference base in enterprise accounts — the proof that skeptical buyers already trust the product in production. That is why acquirers pay revenue multiples that look high against ARR (Accenture–Dragos at ~20× ARR; the AI-security sweep at pre-scale): they are buying trust that would take them years to build organically, plus the team that built it.

This produces three reads for a sale process. First, founder-readiness: a company whose growth has stalled often has a time-to-trust problem, not a product problem — it converted its design partners but never built the flywheel — which is a fixable, sellable story to the right strategic buyer who can lend its own trust. Second, timing: the optimal sell-side window is after the reference flywheel turns (the buyer can underwrite real traction) but before growth decelerates below the IPO bar — the same Year-2-to-5 window the PE clock targets. Third, buyer-matching: a startup with deep references in one vertical (say, defense or financial services) is worth most to the strategic that wants instant credibility in that vertical — the buyer-universe mapping on 11b.


See also

Sources: Ent emerges from stealth, $100M seed (Business Wire, Jun 16 2026); SecurityWeek — Ent $100M seed; "Time to trust" framing — Venture in Security (Ross Haleliuk).


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.