I’m a serial entrepreneur, cyber-security researcher and a software engineer with over a decade of experience and I just started my next venture, Phish.AI. I decided to share in a series of blog posts important milestones, insights and lessons learned along my new journey. Some of the ideas are inspired by the excellent book “The Lean Startup” of Eric Ries, mixed with my own way of thinking and experience (I won’t go into technical details of my startup here, you can read more about it on the startup website but I’ll go over the main business ideas).
One of the main concepts in the book “The Lean Startup” is that when you have a business idea you have many assumptions or hypotheses that are called leaps of faith and you need to validate them as fast as possible and decide if you want to pivot or persevere based on the validation. A startup failing this will soon run out of money. My two cents here are that sometimes it’s very time or resource consuming to validate the hypothesis, so to move on I used the 80–20 percent rule (where to do 80% of the work takes 20% of the time and to do the last 20% of work takes 80% of the time). To validate each hypothesis I did 80% of the work and I continued to the next one with 20% uncertainty. The advantage is that it allows me to be fast on my feet while I take into account that there will always be uncertainties in every hypothesis.
In this post I’ll present 5 hypotheses and how I validated them.
Concept
In the last decade the cyber-security industry transformed massively along with the entire internet landscape. Some aspects of security evolved considerably — including secure software development, web technologies, isolation technologies, encryption and many more. But some didn’t change nearly as much like phishing scams where websites that looks exactly like legitimate ones are actually a clone of the website that is hosted on a different domain. For example, you may accidentally input your Office365 login and password in an attacker’s site that only looks like Office365. Phish.AI tackles this issue by employing modern artificial intelligence and computer vision techniques to build an “automated virtual cyber expert” that can look at an image of a website and detect if the site is similar to a known website but hosted on a suspicious domain.
Hypothesis #1 — Is the technology feasible?
The first thing I validated is whether the tech can learn to recognise good websites and then detect with good accuracy phishing sites that look alike and have a low false positive rate on other websites that are legitimate.
After I developed my first Proof-Of-Concept I ran a benchmark on more than 1,000,000 sites and got astonishing results of over 90% percent detection rate and 0% false positive.
These results, alongside the first version of the Proof-Of-Concept made me comfortable enough (With the 80–20% rule) to move on to the next Hypothesis.
Hypothesis #2 — Is the technology fast enough?
Because the technology sits in the cloud and gets screenshots from a browser extension, I need the analysis to be done in real-time in order to block and prevent malicious websites (otherwise the user already got phished). The first version of the Proof-Of-Concept was too slow, but after a few more development iterations I succeeded in bringing the response time to under 600ms. It was time to move on to the next hypothesis.
Hypothesis #3 — Good gross margin (fancy way of saying is it cheap enough so we can be in business)?
I won’t share the exact cost as it is sensitive information but I’ll share the ballpark. Let’s assume the product costs 4$/user/month. A good gross margin for a SaaS product should be over 80% so the cloud costs should be below 0.8$/user/month. Because this doesn’t include the cost of support and R&D, in a good situation the cloud costs should go below 0.4$/user/month (90% gross margin) — in this case we have a 10% buffer for services and for mistakes I made in this very early calculation.
After a few runs and optimizations, the cost for the third version got to about 0.6$ (Again, this is a ballpark calculation, as I don’t share the exact figures).
Hypothesis #4 — Would I use the product?
Now it was time to build a minimal first version of the product and see if I would use the product myself — I can’t sell something that I wouldn’t use myself.
I built the first version of the product over google cloud (maybe I’ll write a different techy post about the technology stack I used), including the AI and Computer Vision Backend, administrator dashboard and a chrome extension for my browser.
I’m constantly using the extension now, as well as a few friends and family (Although I’m not in the typical phishing target demographic, the product blocked a few phishing sites for me.). More importantly, I can now demo the first version of the product. 80% done, time to move to the next stage.
Hypothesis #5 — Will people pay for it?
This is probably the most important question for the business. In order to sell my product I needed basic marketing. I built and launched the website with an expense of only 100$.
I started generating leads and I now have a few potential customers.
I’m not done with this Hypothesis yet but subscribe to my page and I’ll write the next part shortly — as with the lean startup methodology you have to iterate quickly.
Next time, I will try to find out the answer to the question — “Are people buying the product for the reason you expect and using it the way you expect?” and “Is the market big enough?”
Hope you enjoyed the first part of this series.
Thanks to my brother Shimon Pats and my friend Alon Liv for editing.
Original Post on Medium
[link] [comments]
from Entrepreneur http://ift.tt/2F4PmkQ
via IFTTT
add adsense to blogger
how much money do bloggers make? can blogs make money? make money off ads how to get money from blogging? best websites to make money blog adsense income earn from blogging website ideas to make money how websites make money?
No hay comentarios.:
Publicar un comentario