newsfilter.io
Fireside Chat, Interview, Conference Presentation

a16z Podcast | The Fundamentals of Security and the Story of Tanium’s Growth

  • Orion Hindawi (Tanium co-founder) asserts that enterprise security should prioritize "block and tackle" hygiene—specifically patch management and endpoint visibility—over "cloak and dagger" nation-state countermeasures, citing that fixing the virtual "windows and doors" is the most effective defense.
  • Tanium's architecture replaces the legacy "hub and spoke" model (central server managing endpoints) with a decentralized topology where clients communicate directly with one another, a redesign that took five years and 12 engineers to build from the ground up.
  • The shift to the new architecture was necessitated by modern environments containing 500,000+ endpoints, virtual machines, and cloud instances, where traditional hub-and-spoke systems designed for 10,000 computers fail to scale.
  • Tanium can coordinate security and remediation actions across hundreds of thousands of endpoints in seconds, whereas legacy solutions require days due to their inability to handle dynamic scale.
  • Hindawi notes that out of the top 10 breaches in the last year, Tanium was procured by eight companies after their existing security measures failed to utilize detected attack indicators effectively.
  • Tanium bridges the gap between security (high urgency, low tangible ROI) and operations (low urgency, high tangible ROI) to justify large deals, with four to five current deals exceeding $10 million each.
  • Tanium leveraged relationships from Hindawi's previous company, BigFix, to deploy beta versions to major clients in production environments over five years before officially taking the product to market.
  • The company targets a $20 billion Total Addressable Market (TAM) in endpoint security and operations, which Hindawi projects will grow due to increasing endpoint counts (10–15% annual growth per customer) and heightened awareness of data loss costs.
  • Large incumbents like IBM are described as unthreatened competitors who are still monetizing 20-year-old architectures and selling to customers at the end of their adoption curve rather than innovating.
  • The "perimeter defense" strategy is deemed obsolete after Tanium discovered a major telco customer had 1,478 unauthorized internet exit points (e.g., bridged home networks, DSL lines) compared to only 22 secured entry points.
  • Tanium does not sell professional services, a decision made to avoid creating "heavy" products; this allows for rapid deployments ranging from one day for 50,000 seats to a few weeks for 500,000 seats without a services revenue model.
  • Tanium's platform approach is expanding via quarterly module releases (e.g., forensics, unmanaged asset discovery) that replace point solutions by utilizing the same underlying data collection for multiple workflows, eliminating the need for multiple agents.
  • Customers have demonstrated immediate ROI by identifying and eliminating unused software licenses (e.g., hundreds of unused SQL Server instances) to fund security investments, effectively making security upgrades "free."
  • Hindawi argues that 5% of cyber spend is typically allocated to essential hygiene, a figure he deems insufficient because most companies rely on legacy antivirus and network tools that assume prevention is possible against sophisticated, targeted malware.
  • Tanium's value proposition shifts from prevention to speed, aiming to identify and neutralize threats in seconds rather than days, ensuring the attacker is slower than the defender.
  • Tanium is exploring embedding its communication architecture directly into silicon (via Intel and Qualcomm chips) to manage IoT and mobile devices, bypassing the inefficiencies of software agents and the restrictive "sandbox" models of Apple and other mobile OS vendors.
  • Hindawi states that Tanium currently does not offer a mobile MDM solution because iOS and Android management models are "broken" from an enterprise perspective, preferring instead to wait for hardware-level management solutions.
  • The company is actively displacing point solution vendors by offering a unified console that reduces "MLA" (Multi-Legacy Application) complexity, allowing customers to rip out competing software and consolidate licensing costs.