Snyk’s late 2015 deck is a masterclass in category creation, arguing that security must shift from a perimeter-based 'gate' to a developer-owned 'tool.' With only 8 slides, the deck focuses heavily on the 'Why Now'—specifically the explosion of unchecked third-party code, which Snyk claims accounts for over 90% of applications (Slide 4). The presentation eschews complex product screenshots for a clear philosophical shift: replacing high-entry-price legacy security with a self-serve, 'pull' model inspired by New Relic and GitHub (Slide 5). While it lacks specific traction metrics or a formal '…
Key takeaways
- The deck positions Snyk as the 'New Relic for Security,' signaling a shift toward developer-oriented monitoring and prevention (Slide 2).
- Snyk identifies a massive talent gap, stating that coders outnumber security professionals by an estimated 50-100x (Slide 3).
- The 'Why Now' is driven by the fact that unchecked third-party code and domains account for more than 90% of applications (Slide 4).
- The business model is built on a 'Pull' sales model, utilizing self-serve trials and scaling prices rather than high-entry-price legacy contracts (Slide 5).
- Snyk highlights a critical vulnerability gap: only 41% of reported vulnerabilities in open source are fixed, with a mean time to repair (MTTR) of 390 days (Slide 6).
- The founding team brings deep domain expertise, including experience at IDF 8200 and leadership roles at companies like Akamai, Watchfire, and Gita (Slide 7).
- Market sizing is segmented into Web Security ($2.5B), App Vuln Assessment ($838M), and Automated SW Quality ($1B) (Slide 8).
- The deck lacks any mention of current revenue, user growth, or the specific amount of capital being raised.
Executive Summary: The Developer-First Security Pivot
The Snyk investor deck from late 2015 is a concise, 8-slide argument for a fundamental shift in the cybersecurity industry. At the time of this deck, security was largely seen as a 'gate'—a final check performed by a specialized team before software went live. Snyk’s thesis was that this model was broken because developers were moving too fast and third-party code was too prevalent. By positioning themselves as 'Web Security for Developers,' Snyk aimed to capture the burgeoning DevOps movement.
Slide 1: Title and Positioning
The cover slide features the Snyk logo—a stylized 'spy' or 'hacker' icon—and the tagline 'Web Security for Developers.' This immediately establishes the target persona. Unlike traditional security firms that sold to the CISO (Chief Information Security Officer), Snyk’s primary audience is the person writing the code. The simplicity of the slide suggests a focus on brand identity and a clear, singular mission.
Slide 2: The 'So Now You Know' Value Proposition
Slide 2 defines the product category. It describes Snyk as 'Developer Oriented Web Security Tools' focused on 'Application Security Monitoring & Prevention.' Key technical differentiators mentioned include 'code instrumentation & machine learning.' Most importantly, it uses a high-growth benchmark: 'New Relic for Security.' By tethering their identity to New Relic, Snyk communicates a SaaS-based, developer-centric, and highly scalable business model that investors in 2015 would have easily understood.
Slide 3: The Talent Gap and Tooling Friction
This slide addresses the structural problem in the market. Snyk points out that 'Coders outnumber security people by est. 50-100x.' This creates a bottleneck where security teams either don't exist (in small companies) or are overwhelmed. The slide also critiques existing vendors, stating they are 'extremely not dev friendly' and 'operate outside the app.' The argument is that security must move inside the application logic rather than relying on perimeter-based insights like HTTP logs, which are often 'reverse-engineered' and inaccurate.
Slide 4: Why Now? The Third-Party Explosion
The 'Why Now' slide focuses on the increasing velocity of development. It notes that 'security audit gates' are no longer viable in a DevOps world. The most striking statistic here is that 'Unchecked Third Party code & domains account for >90% of application.' This highlights a massive blind spot: companies are securing their own code but ignoring the vast majority of the software stack they actually deploy. Snyk also references 'The New Kingmakers,' a nod to the growing power of developers to drive purchasing decisions within the enterprise.
Slide 5: The Business and Sales Model
Slide 5 outlines how Snyk intends to go to market. It explicitly lists 'Dev-Friendly companies' like GitHub, Heroku, and PagerDuty as models. The strategy involves replacing traditional 'Security Events' with 'Developer Events' and moving from 'High Entry Price' to 'Free & Scaling Prices.' The 'Pull' model (self-serve) is a direct challenge to the heavy, top-down sales cycles typical of 2015-era security software. This slide is crucial for showing how Snyk will achieve efficient customer acquisition costs (CAC).
Slide 6: The Third-Party Code Problem
This slide dives deeper into the technical 'Massive Security Problem.' It provides a specific, damning metric: 'Only 41% of reported vulns in open source are fixed, MTTR is 390 days.' By highlighting that inventorying modules is 'hard' and auditing is 'infeasible,' Snyk positions its automated tool as the only logical solution to a problem that has grown beyond human capacity to manage manually. It also mentions the risk of 'malvertisements' and malicious 3P domains, expanding the scope of the threat.
Slide 7: The Founders
The 'Founders' slide is perhaps the strongest in the deck in terms of credibility. Guy Podjarny’s background includes the IDF 8200 unit, creating the first WAF (Web Application Firewall), and serving as CTO at Akamai. Danny Grander also brings IDF 8200 experience and a history of leading dev teams at security startups. Assaf Hefetz rounds out the trio with a background in digital identity and cyber work for the Israeli Prime Minister’s Office. For a seed or early-stage round, this level of domain expertise is a significant de-risking factor for investors.
Slide 8: Market Size and Comparables
The final slide quantifies the opportunity. Snyk cites IDC predictions for 2018, valuing Web Security at $2.5B and App Vuln Assessment at $838M. To justify potential returns, they list 'Comparable Companies Valuations,' including New Relic ($1.6B), AppDynamics (>$1B), and Imperva ($2.1B). This slide attempts to show that even a small slice of these converging markets represents a billion-dollar opportunity.
What Snyk Does Well
Category Definition: Snyk does an excellent job of explaining why the old way of doing security is dead. By focusing on the 'Developer-First' angle, they aren't just another security tool; they are a new category of software. Using New Relic as a North Star is a brilliant way to explain a complex technical shift in simple business terms.
Problem Quantification: The deck uses specific, painful numbers—like the 390-day MTTR for open-source vulnerabilities—to create a sense of urgency. They don't just say third-party code is a problem; they state it makes up 90% of the app, making the problem feel unavoidable for any modern tech company.
Founder-Market Fit: The team slide is impeccable. In cybersecurity, pedigree matters immensely. Having multiple founders from the IDF 8200 unit and former CTOs of acquired companies tells investors that this team has the technical chops to build what they are promising.
What is Missing from the Deck
Traction Metrics: There is a total absence of data regarding Snyk's own progress. We don't know if they have 10 users or 10,000. There are no mentions of early pilot customers, GitHub integration stats, or even a beta waitlist. This suggests the deck was used very early in the company's lifecycle, likely for a seed round where the 'vision' and 'team' were the primary selling points.
Product Visuals: For a tool that claims to be 'developer-oriented,' the deck lacks any screenshots of the interface or the CLI (Command Line Interface). Investors are left to imagine how the tool actually integrates into the developer workflow. Showing a 'before and after' of a developer finding and fixing a vulnerability would have strengthened the pitch.
The Ask: The deck ends abruptly after the market size slide. There is no information on how much capital is being raised, the valuation expectations, or the specific milestones the team intends to hit with the new funding. This is a common omission in 'short' versions of decks, but it leaves the narrative unfinished.
What Other Founders Should Copy
The 'Why Now' Logic: Founders should look at Slide 4. Snyk doesn't just say 'security is important.' They explain that dev velocity has increased and third-party code has exploded, making the old way of doing security impossible. Every pitch needs a 'Why Now' that feels like an unstoppable force of nature.
The Comparable Model: If you are building in a new category, find a successful company in a parallel category and call yourself the '[Successful Company] for [Your Category].' It is a shortcut to investor understanding. Snyk’s use of New Relic is the gold standard for this technique.
Focus on the User, Not Just the Buyer: Snyk’s emphasis on the developer (the user) rather than the CISO (the buyer) was a radical shift in 2015. Founders building enterprise software should consider if there is a 'bottom-up' adoption story they can tell, focusing on the people who will actually use the tool every day.
Frequently asked questions
- What is the core problem Snyk aims to solve according to the deck?
- Snyk targets the disconnect between rapid software development and slow security audits. Slide 4 notes that 'dev velocity is increasing,' making traditional security gates non-viable. Furthermore, Slide 6 emphasizes that modern web apps are mostly composed of third-party code, which is often untested and has a massive 390-day average time to fix vulnerabilities, creating a significant security debt that legacy tools cannot address.
- How does Snyk plan to acquire customers?
- Snyk explicitly rejects the traditional 'push' sales model of enterprise security. Slide 5 outlines a 'Pull' model modeled after developer-friendly companies like GitHub and PagerDuty. This involves community participation, developer relations, and a 'self-serve try, use, buy' funnel. They aim to replace 'High Entry Price' products with 'Free & Scaling Prices' to lower the barrier to adoption for individual developers.
- What is the 'New Relic for Security' comparison intended to convey?
- This comparison, found on Slide 2 and Slide 5, suggests that just as New Relic moved performance monitoring into the developer's daily dashboard, Snyk will do the same for security. It implies a product that is instrumented directly into the code, provides real-time insights, and is designed for the person writing the software rather than a separate security officer sitting outside the development loop.
- Why is the founding team considered a strength in this deck?
- Slide 7 showcases a team with elite technical and entrepreneurial backgrounds. Guy Podjarny was a CTO at Akamai and founded a company sold to them; Danny Grander was a Security Research Manager at a firm acquired by Verint. Crucially, two of the three founders served in the IDF's 8200 unit, a world-renowned incubator for cybersecurity talent, providing immediate credibility to investors in the security space.
- What metrics are missing from this pitch deck?
- This is a vision-heavy deck that omits almost all operational metrics. There is no mention of current user counts, GitHub stars, number of vulnerabilities indexed, or revenue. Additionally, the deck does not include a 'The Ask' slide, meaning it does not specify how much money the company is looking to raise or how those funds will be allocated to achieve future milestones.