The IriusRisk pitch deck is a masterclass in logical sequencing, moving from a quantified problem—that fixing security flaws after release is 100x more expensive than during design—to a scalable automated solution. By focusing on the 'Shift Left' philosophy, the company positions itself not just as a security tool, but as a business efficiency enabler. The deck effectively uses regulatory tailwinds, such as PCI and GDPR, to create urgency. While it lacks explicit financial performance metrics in this version, the focus on total addressable market (TAM) of $248B and a clear rollout strategy fo…
Key takeaways
- The deck quantifies the problem by stating that 50% of software security vulnerabilities are flaws in the design (Slide 3).
- It uses a stark bar chart to show that fixing flaws at the release stage is 100x more expensive than at the design stage (Slide 3).
- The solution is framed as 'starting left,' reducing threat modeling time from days to minutes (Slide 6).
- The company identifies a $12B Serviceable Addressable Market (SAM) within a $248B total cybersecurity market (Slide 9).
- IriusRisk positions itself as a 'Secure Design' leader, differentiating from static code analysis (Fortify, Checkmarx) and dynamic testing (Qualys, WhiteHat) (Slide 7).
- The deck leverages regulatory deadlines, noting that PCI mandates threat modeling for all payment providers starting October 2022 (Slide 12).
- The team slide highlights deep domain expertise, including a founder with 20 years of AppSec experience and the author of 'Threat Modeling: Designing for Security' (Slide 2).
- The strategy includes a mid-market expansion via a Jira Plugin to enable 'SAST for Architecture' (Slide 10).
Introduction: The Shift-Left Security Thesis
IriusRisk entered the Series B market with a clear, defensible thesis: security is a design problem, not just a coding problem. By the time a developer writes a line of code, half of the potential security vulnerabilities are already baked into the architecture. This deck, used to secure a portion of their $37,200,000 total funding, focuses heavily on the economic irrationality of the status quo. It argues that the current manual approach to threat modeling is unscalable, expensive, and a bottleneck to digital transformation.
Slide 1: Title and Brand Identity
The cover slide features the company logo and the tagline "Secure your software by design." It includes a team photo, which is a common tactic to humanize a highly technical B2B software product. The visual metaphor of a laptop with a lock and digital circuitry reinforces the application security (AppSec) focus. It is a standard, professional entry point that establishes the domain immediately.
Slide 2: The Leadership Team
IriusRisk places its team slide second, which is a bold move that signals the strength of their human capital. Stephen de Vries (CEO) is credited with 20 years of AppSec experience and founding the OWASP Java Project. The inclusion of Adam Shostack as a Technical Advisor is a significant 'trust signal,' as he is the author of the definitive textbook on the subject, "Threat Modeling: Designing for Security." The slide also lists previous investors like JME Ventures and Swanlaab, showing existing institutional backing.
Slide 3 & 4: The Quantified Problem
These slides are the heart of the pitch. Slide 3 states that 50% of software security vulnerabilities are design flaws. It cites Dr. Gary McGraw and the IEEE Center for Secure Design. The most compelling visual is the bar chart showing the cost of fixing flaws. Fixing a flaw during the 'Design' phase is the baseline (1x), but that cost balloons to 15x during 'Testing' and a staggering 100x after 'Release.' Slide 4 elaborates on why manual modeling fails: it takes 3 days and costs $3,000 per application. For a bank managing 3,000 apps, the math simply doesn't work for manual processes.
Slide 5 & 6: The Answer and The Solution
Slide 5 introduces the concept of "START LEFT." This is a play on the industry term 'Shift Left,' suggesting that security should be an enabler of growth rather than a barrier. Slide 6 provides the specific ROI. It compares the €9,000,000 cost of manual modeling for 3,000 apps against the IriusRisk self-service model (though the specific price is redacted in this version). The key value points are: time reduced from days to minutes, actionable advice for developers, and full traceability for regulated industries.
Slide 7: The Secure Development Process
This slide is a competitive landscape map disguised as a workflow diagram. It shows the three stages of development: Design, Build, and Test. IriusRisk claims the 'Design' circle, positioning itself before established giants like IBM, HP, Fortify, and Veracode (who occupy the 'Build' and 'Test' circles). By doing this, IriusRisk avoids a direct feature-war with incumbents and instead positions itself as the necessary precursor to their tools.
Slide 8: How It Works
This is a technical architecture slide. It shows the IriusRisk platform generating threat models, updating risk ratings, and pulling/pushing data to ALM (Application Lifecycle Management) and issue trackers like Jira. It visualizes the integration between architects, developers, and security teams, proving that the tool isn't a silo but a connective tissue in the dev stack.
Slide 9: Market Sizing (TAM/SAM/SOM)
IriusRisk uses a traditional concentric circle diagram for market sizing. They cite a $248B total cybersecurity market (TAM) for 2023. They narrow this down to a $12B Serviceable Addressable Market (SAM) for security testing. Their Serviceable Obtainable Market (SOM) is $1.2B, based on a conservative 10% penetration. The slide includes citations for these figures, which adds credibility to the projections.
Slide 10: Market Strategy and Product Roadmap
This slide uses a pyramid to show security maturity. The top (Fortune 1000) is the current target, where manual threat modeling is already happening. The middle (Fortune 2000) is the growth area. The bottom (Mid-market) is the future opportunity. Interestingly, they mention a planned Jira Plugin to address the mid-market, described as "SAST for Architecture." This shows a clear path from high-touch enterprise sales to a lower-friction, per-user marketplace model.
Slide 11: Typical Rollout Example
This slide addresses the 'how' of enterprise adoption. It acknowledges that companies usually only model 15% of their apps. Phase 1 uses IriusRisk to automate that 15% for security architects. Phase 2 expands to the other 85% by enabling engineering teams to self-service. This two-step approach reduces the perceived risk of a massive organizational change.
Slide 12: Market Timing and Traction
The final slide combines a 'Top of Funnel Progress' chart with a 'Market Signals from Regulation' table. The bar chart shows a clear upward trend in contacts and leads from Jan 2019 to Jan 2020. The regulation table is the 'Why Now?' factor. It lists PCI, IEC 62443, ISO 21434, and GDPR as mandatory drivers. The mention of the PCI mandate in October 2022 creates a hard deadline for potential customers and investors alike.
What Works in the IriusRisk Deck
The deck is exceptionally strong at quantifying the pain point . Many security startups talk vaguely about 'reducing risk,' but IriusRisk puts a specific dollar amount and a 100x multiplier on the cost of delay. This speaks directly to the CFO, not just the CISO. Furthermore, the competitive positioning on Slide 7 is brilliant. By defining a new category ('Secure Design') rather than trying to be a 'better' static analysis tool, they carve out a blue ocean for themselves. The regulatory timeline on the final slide provides the necessary urgency that often lacks in B2B SaaS pitches.
What is Missing from the IriusRisk Deck
While the deck is logically sound, it is light on financial traction . We see 'Top of Funnel' growth, but there are no slides dedicated to Annual Recurring Revenue (ARR), Net Revenue Retention (NRR), or Customer Acquisition Cost (CAC). For a Series B deck, investors usually expect to see a 'Money In, Money Out' engine. Additionally, there is no 'Ask' slide in this version. We don't know how much they were raising in this specific round or how they intended to deploy the capital (e.g., 50% sales/marketing, 30% R&D). Finally, while they mention 'Fortune 500 banks' in their description, the deck would benefit from a dedicated customer logo slide to prove social proof.
What a Founder Should Copy
Founders should emulate the ROI calculation on Slide 6. If you are selling to enterprises, you must show them how your tool pays for itself. IriusRisk does this by multiplying the number of apps by the days saved by the daily rate of an expert. It is a simple, undeniable formula. Also, the 'Typical Rollout' slide (Slide 11) is a great way to handle the objection that 'our organization isn't ready for this yet.' By showing a phased approach, you make the sale feel like a journey rather than a disruptive event. Lastly, use third-party validation for your problem statement. Citing the IEEE and Dr. Gary McGraw makes the '50% of flaws are design flaws' claim feel like an industry fact rather than a marketing pitch.
Frequently asked questions
- How does IriusRisk define its market opportunity?
- IriusRisk segments the market into three tiers. The Total Addressable Market (TAM) is the $248B cybersecurity market. The Serviceable Addressable Market (SAM) is the $12B security testing market. Their Serviceable Obtainable Market (SOM) is estimated at $1.2B, based on a 10% penetration of the SAM. They specifically target Fortune 1000 and 2000 companies in financial services and high tech.
- What is the primary value proposition for enterprise clients?
- The core value is cost avoidance and speed. Manual threat modeling for a large financial institution with 3,000 apps per year would cost approximately €9,000,000 (3,000 apps x 3 days x €1,000/day). IriusRisk automates this process, moving the timeline from days to minutes and allowing developers to self-service security advice without needing constant intervention from scarce security experts.
- Who are the competitors mentioned in the deck?
- The deck categorizes competitors by development stage. For 'Secure Design,' it lists alternatives like 'Do nothing,' Excel/Visio, Microsoft Threat Modeler, MyAppSecurity, and SD Elements. It distinguishes itself from 'Build' stage tools like Fortify and Veracode, and 'Test' stage tools like Qualys and Acunetix, by focusing entirely on the design phase.
- What regulatory factors are driving IriusRisk's growth?
- The deck cites several key regulations: PCI (mandating threat modeling by Oct 2022), IEC 62443 (mandatory for industrial systems), ISO 21434 and UNECE WP.29 (mandatory for vehicle systems), and GDPR (requiring data protection by design). These regulations transform threat modeling from a 'nice-to-have' into a legal requirement for enterprise software.
- What is the 'Typical Rollout Example' described in the deck?
- The rollout is a two-phase process. Phase 1 focuses on 'Threat Model Automation' for the 15% of applications already being modeled, acting as a productivity tool for security architects. Phase 2 targets 'Self-Service Threat Modeling' for the remaining 85% of applications, empowering solution architects and team leads to handle security design themselves.