This year at Black Hat, the great Anna Suslova and Ryan Morasco came up with an amazing idea: instead of the boring, usual events…why not rent excavators and crush cars?





This year at Black Hat, the great Anna Suslova and Ryan Morasco came up with an amazing idea: instead of the boring, usual events…why not rent excavators and crush cars?





We went to Speed Vegas on the first day of our QBR/Black Hat adventure. As a massive Porsche fan, I was pumped to drive a Porsche GT3 RS. As a very careful driver, I was incredibly slow. The slowest – in fact – driver that day.










I was at Black Hat in Vegas for less than 24 hours, and Randi and Maggie decided we needed to add a second dog. This is Travis, an Aruban Cunucu.

TLDR; When Nagomi emerged from stealth in April, we noticed that any time we linked to nagomi.security on LinkedIn, it would be flagged as “Possible Malicious Content.” Here’s why and how the issue was resolved. And some interesting findings…..
I’ve worked at several cybersecurity companies, but I’m not a researcher, engineer, or any flavor of legitimate security practitioner. I was a developer back in the stone age (early 2000s), but I don’t claim any expertise whatsoever. There’s a high probability that I’ll get some stuff wrong, so I figure I should start with that.
If you’ve ever launched a company and its website from stealth, you’d know that it’s a lot like a duck swimming. On the surface it looks calm and natural. Underneath it’s web-footed chaos.

But this one was actually pretty straightforward with very few hiccups. In fact, I remarked that this was one of the easiest site launches I’ve ever done. Which is why the next part happened. The universe loves a gloater.
Right after launching the site, I launched our LinkedIn page. And immediately I noticed something weird: as soon as I put in nagomi.security as our site URL and URL for a CTA button, I saw that the URL was overwritten and went to:

And after playing around a bit, I noticed that ANY .security TLD was getting overwritten. But that didn’t make sense…there are plenty of companies that have .security domains….
I then saw that any time we posted from the Nagomi Security LinkedIn page, if we linked to, say:
https://nagomi.security/what-is-credential-stuffing-and-how-can-cybersecurity-teams-use-existing-tools-to-minimize-the-threat/
Clicking that link would result in:

I reached out to LinkedIn support about the issue and got the following reply (and quickly):

Going to VirusTotal, we saw:

Two security tools listed in VirusTotal dinged us for having a “newly registered domain name”. Although the domain was registered in January….

…I guess “newly registered” is subjective.
We then reached out (via form fills) to the 2 vendors to get out of domain jail. Meanwhile….
Filling out forms isn’t exactly the most urgent path to getting a problem solved, so in the meantime we needed to share our content and build a following for our LinkedIn page. I found a couple of workarounds – each with quirks.
Workaround 1: A .com Domain Forwarding to the .security Domain
A few days before registering nagomi.security, we registered nagomisecurity.com

That domain just forwards to nagomi.security, so if we want to promote the blog post that’s at:
https://nagomi.security/what-is-credential-stuffing-and-how-can-cybersecurity-teams-use-existing-tools-to-minimize-the-threat/
we could just use:
https://nagomisecurity.com/what-is-credential-stuffing-and-how-can-cybersecurity-teams-use-existing-tools-to-minimize-the-threat/
It works, but it’s kind of long. LinkedIn uses its own URL shortener, so the long URL above would end up being: https://lnkd.in/eJUbqRtt Problem solved, but that’s odd. LinkedIn is okay with a URL that forwards to a domain flagged in VirusTotal. So wait…..what about…
Workaround 2: A Bitly URL
If LinkedIn is cool with a redirect, then would they allow a URL shortener like bit.ly?

Yep! When you buy a bit.ly subscription, you get a new domain registration

On April 23rd, while still serving our sentence in new URL jail, I registered nagomi.ws and then started creating shortlinks to nagomi.security. It works every time. Here: https://nagomi.ws/youre-so-vain That goes to my LinkedIn profile. This one goes to our super popular credential stuffing blog post https://nagomi.ws/4bjnnga
On April 29th, I got the following message:

24 hours after being cleared by VirusTotal, LinkedIn should drop the warning. Then, on May 20th, I checked VT and we were clear! But we were still being flagged as malicious. I reached out to LinkedIn and let them know that although we were clear in VirusTotal, our links were still getting marked as possible malicious content.
Then, the next day I got a message:
I looped in our Trust and Safety and they let me know website link was caught by one of our security vendors but has been cleared since.
Fixed!

First, LinkedIn uses VirusTotal to check links and if any vendor on VT says you’re a potential problem, you get flagged. So if you’re emerging from stealth and plan to use LinkedIn, check VirusTotal before launch. It might take a while to get cleared.
Second, register your domain months before you plan on launching. You can get dinged for a “new domain” even when your domain is hundreds of days old…..
….unless
Unless you want to use a brand new forwarding domain like bit.ly. Not only does that skip the “newly registered domain” issue, it allows you to forward to any domain you want! Which begs the question: does LinkedIn have a suppression list for domains so that if they’re known to be owned by a URL shortening service they skip the VirusTotal check?
Thirdly, LinkedIn support was very helpful, super responsive, and without their escalation path I don’t think the issue would have resolved itself. It’s not their fault that VT marked us as potentially malicious, and as soon as they saw we were in the clear, they let us out of jail immediately. Kudos to them!
Fourthly and finalthly – This security research stuff is fun! I’m not going to quit my day job, but I see why people love going down the rabbit hole. And if you’ve made it this far, thanks for reading…and please let me know what I got wrong. I’m sure there are errors. Just not the word “finalthly”. That’s correct.

Today we’ve announced that Nagomi Security has emerged from Stealth with $30 million in funding. The company operated in stealth mode with Seed funding from Team8, and the recent round was led by TCV, with participation from CrowdStrike Falcon Fund and Okta Ventures. Nagomi is also backed by leading angel investors, including Shlomo Kramer, co-founder and CEO of Cato Networks, Nir Polak, co-founder and CEO of Exabeam, and Guy Podjarny, Founder of Snyk.

After 6+ years of career-defining work at Axonius, I knew I had to get back to early stage. I am incredibly proud of what we were able to accomplish, the team we built, the product, and I have nothing but great things to say….I mean….I have a tattoo on my arm to prove it. Going from zero to $100 million in ARR is a massive accomplishment, and I can’t say enough about the team that made it happen.
But it was time. I was always conscious of the fact that – at some point – there would be someone better to run marketing at a certain level of size and scale. Knowing that I love the early, chaotic stage from stealth to $100 million, balanced with knowing that there is someone out there that loves the $100+ million stage, it became clear to me that it was time to move on.
When I made the decision to do something new, I had to choose whether to start something myself or join an existing startup. And I had an idea that was bothering me. Despite all of the tools we have in cybersecurity, how do we know whether they’re actually providing value and working effectively? Other than the binary “did I get breached?” how can we tell whether what we buy is both working and providing value? And in both cases, how do we measure progress?
I had incredible guidance from investors that thought the problem space was interesting enough to explore. And when I spoke to one investor specifically, he said something like “not only do I love the problem space, I invested in a company a year ago that’s working on exactly that problem. You should talk to them.” So I did. And they were. So I am, too.
Cybersecurity is hard. You buy a bunch of tools, configure them on day one, and then move on to something else. But threats change, cyber criminals pivot, and tools add functionality over time. But with cybersecurity teams constantly stretched thin, and practitioners underwater with too many threats to possibly investigate it becomes incredibly difficult to ensure that the tools we have at our organizations are configured properly against the real-world threats targeting us.
What if there were a way to connect all of your security tools to a brain that:
That’s what Nagomi does. By connecting to the security tools an organization already uses, it then compares that to threats like ransomware and phishing, then gets more granular looking at the specific threat actors and campaigns, analyzing the configuration of the stack, and providing evidence-based suggestions on how to decrease threat exposure.
Big.
Much like it was in the early days at Axonius, every person I talk with has the problem. At Axonius I’d ask “how many devices do you have?” and would get either “I don’t know” or “between 10 and 30,000.” Here, when I ask “how do you know whether your security tools are effective against Black Cat ransomware, and do you have any exceptions? What about compensating controls?” I hear “It’s incredibly manual, and we’re trying to figure out how to solve it.”
One of our customers put it best: “You buy a bunch of tools and have them configured perfectly on day one. But then you move on to other things, a year goes by, and you know that there are either new features or changes that could make your defenses more effective against changing threats. I want to know where my controls are degraded, where I am exposed, and what I can do to close that gap and move the needle.”
I like an analogy, so here goes:
Great question. We just emerged from stealth today, and our awesome new site is nagomi.security – huge thanks to the team at CNP who put up with my aggressive timeline and dumb questions. They really do great work (I’ve worked with them at 3 different companies).
And if you’ll be at RSA, come see us! You can schedule a time here, or send a message and we’ll find a time to talk!

































Today we released the final installment of the Axonius film series with Simone Biles, Controlling Complexity: Growth. This post looks at why we did it, how we evaluated whether it was successful, and what we learned from a 2 year adventure.
Today we’re launching the final chapter in our 3 part series with Simone Biles. You can see Controlling Complexity: Growth here.

In a word: awareness. When we first started Axonius, we knew that the larger the organization, the more acute the pain they felt around knowing what assets they had, uncovering risk, and automating action. But a few years after launching the first cybersecurity asset management solution, we noticed that smaller organizations were feeling the exact same pain.
But as a young company, we didn’t have the brand awareness for the masses. In fact, when we did our first aided recall survey only 9% knew who we were. In other words, 91% of our target audience didn’t know Axonius existed.
Which led us to do two things:
We could talk about cybersecurity asset management, becoming the system of record for digital infrastructure, and all of the amazing product features we have. But we needed a big theme to hang those from. We needed that big, lofty idea to concisely tease the aspirational value.
Q: What is the thing that Axonius customers get when they buy our product(s)?
A: They are able to control complexity.
Complexity is inevitable. It’s the 2nd law of thermodynamics, and it’s true in our everyday lives. Over time, things get more complex. And that’s what we see at organizations we work with. They add more people, more devices, SaaS applications, cloud instances, and tools to manage and secure them all.
This fragmentation is what leads to many of the IT and security challenges organizations face today. But if they were able to collect, aggregate, and correlate data from all of the sources that know about assets, they would be able to know what they have, uncover risk, and decide what to do when any asset deviates from their expectations.
In short: we help organizations control the inevitable complexity they will face as they grow.
Great. We have a theme that fits. Now what? Well now we needed to figure out how to tell that story.
Cybersecurity vendors (and tech in general) tend to rely on talking about military-grade features, real-time detection, and lead with FUD. They rarely focus on the people behind the software and hardware. The hacker behind the hoodie.
We wanted to focus on the human beings that know working in cybersecurity isn’t a fair fight, but they show up every day anyway.
We wanted to find a public figure that represented the idea behind the campaign. Someone that faced adversity and came out stronger on the other side. Someone that could adapt. Someone that is constantly striving for growth.
I kept coming back to one name: Simone Biles. Arguably the greatest American athlete of all time, she grew up as a foster kid, and the entire world watched her at the Tokyo Olympics. Imagine competing at the highest level under a worldwide microscope. But Simone is one of the most marketable athletes on earth. Why would she choose to work with a cybersecurity company?
You don’t get what you don’t ask for. So we asked.
Meantime, we saw that a video of Amy Bream, a Crossfit athlete born with one leg was going viral. In the video, she’s seen trying to lift a very heavy weight, and fails. She tries again, fails. Tears stream down her face. But she does it again and this time, she nails it. In that video, without any words whatsoever, it encapsulated the spirit of the campaign.
So we reached out to Amy, too.
What happened next is truly unbelievable. They both said yes. And in what I will refer to as the “dog that caught the car” scenario, we had to figure out what to do next. What happens to the Marketing team that got what they wished for?
As Chris Cochran and Ron Eddings so perfectly say:
Cybersecurity professionals are mental athletes with no off-season.
From an Inc. article covering the initial campaign launch:
Still, it invites the question, what does a cybersecurity asset management firm aiming to humanize the field have in common with a gymnastics star, even if that star has been hacked?
Despite the unusual pairing, the answer’s pretty simple: resilience.
“Throughout our lives, we’ll all share adversity and complexity over the course,” Biles tells Inc. “And the ability to persevere through that is what really makes a strong system.”
“We both share complexity,” Biles adds. “Even if it’s in our own different worlds, we both go through it.”
and:
Biles isn’t the only athlete to connect to Axonius’s campaign. The CrossFit champion Amy Bream, who was born without a right leg, is also involved. Along with Biles, the two will discuss how they each take on complexity in their lives in a video series that’s housed on an Axonius video platform. They will also make appearances on podcasts and in-person events.
Our first video with Amy Bream looked at how she focuses on what she can control to overcome adversity.
Followed by the first commercial with Simone Biles
In the second installment, we wanted to highlight how in the face of enormous complexity, the best not only find ways to adapt to the challenge, they also find ways to give back.
Giving back is core to what we do at Axonius. In this chapter, we were fortunate enough to be able to give to Friends of the Children – an organization that provides professional mentors to kids in foster care – and the Morgan family. I don’t want to spoil it. You’ll have to watch:
And now, back to today. We started with the fundamentals of dealing with complexity. We then looked at adapting to challenges. In the final chapter, we finish with the idea that complexity is inevitable, but growth is optional.
To do this, we wanted to bring in people that work in and adjacent to cybersecurity to tell their stories through the vehicle of a letter written to their younger selves. We then had an informal conversation to explore the common threads between a champion athlete and cybersecurity professionals:

Oritse Justin Uku, CISSP is an author, veteran, and Business Information Security Officer. I met him years ago at an event in NYC and stayed in touch. His journey from business school to Afghanistan, finance to cybersecurity is fascinating, and I’ve always thought him to be one of the most inspiring people I know.
Tiffanie Joseph, PSM1 took the leap to put herself through a yearlong cybersecurity program to improve her and her daughter’s life. Her story is evidence that cybersecurity can transform people’s lives.
John Seaman helped us convince Simone to work with us in the first place. John and his family have been involved in orphan care (adopting & fostering), he’s a long-distance runner, and his motto is to leave people, places, and things better than you found them. A truly great human being.
As part of today’s launch, Dean Sysman wrote his own letter to his younger self:
We’re encouraging people to write their own letters to themselves about a time when you overcame complexities of your own.
Use hashtag hashtag#DearYoungerMe and please tag Nathan Burke, Dean Sysman and Axonius in your post so we can read your stories!
People often say that measuring brand is impossible. You just know the absence of it. I disagree.
Though not perfect, I evaluate brand investment in two ways:
I won’t give any numbers here, but I can confidently say that the investment has been well worth it by any measure.
Working with Simone, Amy, and everyone involved with this campaign was truly a career highlight for me. I need to thank many people, and I apologize for anyone I’ve missed.
Kaite Rosa, Karen Dorfzaun, Elizabeth Hartel, Madeleine King, Jeffrey Schleicher, Allen K. and Sky Pak – You transformed a high-level idea into something amazing that you should all be proud of. You accomplished something that is beyond all expectation.
Dean Sysman – You let us run with a crazy idea that no one has ever done before. Thank you.
Stephanie Fox, Micheal B., Jennifer Lynch, Austin Holcomb for all the work behind the scenes on the website and social channels to get this out the door.
Tracey Workman for convincing journalists that this wasn’t a run-of-the-mill vendor stunt, but a story worth telling.
To our great agency partners Stept Studios for producing and editing the final chapter in the series, and to Ruckus for the first two chapters.
To Janey Miller, Drew Johnson and the Octagon team for taking a chance on a cybersecurity company who wanted to do something ambitious.
To Genevieve Jewell Thompson and the Amy Bream team – thank you so much for being a joy to work with.
To Oritse Justin Uku, CISSP, Tiffanie Joseph, PSM1, John Seaman – thank you for letting us tell your stories.
To the entire Axonius team, thank you for supporting this project. I am so proud of the work we’ve done and can’t wait to hear what people think.

If I get the tone wrong, I’ll sound like an old man yelling at kids to stay off his lawn (hence the photo). If I get it right, it’ll be an examination of “always target the top” when selling. You be the judge.
In November, I’ll hit my 6 year anniversary at Axonius. That’s a long time.
In the early days, I was CMO, demo-giver, writer, presenter, speaker, mailer of backpacks (Joseph Hoban will remember that), requester of API access, and generally chief pest. And in those days I still bought stuff.
Fast-forward to today, and we’re a global team with leaders and specialists in nearly every Marketing function. Yet every day I get calls, emails, and LinkedIn messages from people saying some version of:
“I see you’re the CMO, which means you would be responsible for buying click fraud detection solutions / spam attendee lists from events that haven’t happened yet / marketing automation software / explainer videos / partner portals / branded swag. Can we set up 45 minutes to talk and I’ll send you a pair of AirPods / a bluetooth speaker / an UberEats gift card ?”
And every time someone gets through by spoofing a local number or creating a well-crafted subject line that makes me think I know them, I respectfully reply with a version of:
I appreciate the hustle. As someone that runs Marketing at a tech company, I get the game….you have to get meetings in order to generate pipeline. Same. But I have to tell you: I’m not your guy. If you’re selling meetings or events, I have a team for that. Tech to help us automate? MOPS team. Other stuff? Channel, Content, PR, Field/Experiential, Brand…..Am I the guy that approves and says yes at the end? A lot of times, yes. Am I the guy to have a first meeting with? Nope.
Because to me, two things are incredibly important:
Being overbearing and making yourself the only person who evaluates and procures vendor solutions? Terrible idea.
Being totally hands off and telling your team to go buy anything they want? Terrible idea.
There’s a lot of nuance, integration, and understanding how everything fits together if you want to be both efficient and high performing.
I’m not sure it makes sense to always do anything.
But I think in this case, it sort of depends. And this is where I’d like to hear your thoughts.
Fair question. It might be. I’m sure there are CMOs out there that love attending vendor webinars, demos, and want to be involved at the outset. I am not one of them, and can’t understand why anyone would operate like that. I also don’t understand people that like:
And about a million other things.
A long time ago (February 2021) I wrote a similar LinkedIn post: Like robots.txt but for LinkedIn. The idea was to create a way to quickly demonstrate what I’m not at all interested in, what I’m not responsible for, and it would save me AND vendors a lot of wasted time and effort.
More than two years later, I want to resurrect that idea and update it..this time not just for LinkedIn. Now it’s outreach.txt:
//Tell Explainer Video Vendors We're Not Interested User-agent: Explainer-Video-Vendor Disallow: / //Tell Event Vendors Which Team to Contact User-agent: Event-Vendor Allow: Connections Disallow: / Refer: Axonius-Experiential-Team //Tell Lead List Vendors We Don't Buy Spam Lists User-agent: List-Vendor Disallow: / //Tell Martech Vendors Who to Contact User-agent: Marketing-Tech-Vendor Disallow: / Refer: Axonius-Marketing-Ops-Team //Tell PR/Content Vendors Who to Contact User-agent: PR-Content-Vendor Allow: Non-Pay-to-Play-Podcast-Requests, Earned-Media Disallow: Pay-to-Play-Infomercials Refer: Axonius-Content-and-PR-Team //Tell Webinar Vendors Who to Contact User-agent: Webinar-Vendors Disallow: / Refer: Axonius-Programs-Team //Tell Meeting Setting Vendors Who to Contact User-agent: Meeting-Setting-Vendors Disallow: / Refer: Axonius-Programs-Team //Tell Consulting Services Who to Contact User-agent: Consulting-Services Allow: Connections Refer: Kind-of-Depends //Tell Data Enrichment Vendors Who to Contact User-agent: Data-Enrichment-Vendors Disallow: / Refer: Axonius-Marketing-Ops-Team //Tell Outsourcing Agencies Who to Contact User-agent: Outsourcing-Agencies Disallow: / //Tell Sports Team Patch Sponsorship Vendors Who to Contact User-agent: Sports-Team-Patch-Sponsorship-Vendors Disallow: / //Tell OOH Brand Agencies Who to Contact User-agent: OOH-Brand-Agencies Disallow: / Refer: Axonius-Brand-Team //Tell ABM Vendors Who to Contact User-agent: ABM-Vendor Disallow: / Refer: Axonius-Digital-Team //Tell Analyst Firm Vendors Who to Contact User-agent: Analyst-Firm-Vendor Allow: Connections Refer: Axonius-Product-Marketing-Team
If you’ve made it this far, enjoy another AI-generated photo like the header:

What do you think? Am I just venting at what’s inevitable? Outreach is always going to be the same despite it – situationally – being a total waste of time. Or is there a case for understanding context and when it makes sense to have a leader of a function involved on the first engagement?
Or even better….how do we get this outreach.txt thing to become real?

I recently won 2 Schwartz Autographed Boxing Glove Mystery Boxes from Pristine Auction. The video shows what was inside.