Jake Aaron Villarreal: I'm Jake Aaron Villarreal, born and raised in Silicon Valley, and here to take you behind the scenes to share what it's like to be a startup founder, the journey they're on, the problems they face, the products they build, in an effort to make our lives better. I'm excited to have with us today Alan LeFort. Alan, welcome to the show.
Alan LeFort: Thank you for having me, Jake. I'm excited to be here.
Jake Aaron Villarreal: I'm excited to have you here. We had a great call a few weeks back and we'll kind of double down on some of that conversation then and talk about some new stuff today. But uh, a little bit more about Alan, he is the co-founder and CEO of Strongest Layer. Alan has over 25 years building products and scaling go-to-market at Proofpoint, McAfee, and Intel. Alan saw pattern matching break against AI attacks. As both builder and strategist, he's now architecting the reasoning-based detection that gives defenders the advantage against threats legacy systems fundamentally cannot see. And Strongest Layer is pioneering third-generation email security for the AI era. God, there's a lot in there here and I'm excited to jump into it with you. Yeah. Before we do, where, whereabouts you joining us from today?
Alan LeFort: I currently reside in Chicago as of four months ago.
Jake Aaron Villarreal: Really cool. God, that's a great place, great town, and those Chicago Bears are killing it this year in the NFL. So, exciting times. Are you originally from there, or whereabouts you originally from?
Alan LeFort: Uh, well, I'm a bit of a world traveler, but I'm originally uh, born and raised in Canada. So I was Canadian. Um, still am. And uh, you know, lived there into my 20s. And then I uh, I moved to Mexico for a stint. Then I uh, spent 10 years in Toronto, Canada. Then I ended up in the Czech Republic in Europe for a couple years. Cupertino in the Bay Area for a couple years. Dallas for 10. And now Chicago. I uh, I am a citizen of the world.
Jake Aaron Villarreal: I love it. Wow. You've been around. In terms of you, you have a unique background, which is what I, why I wanted to have you come on. You've got the venture side, you've got the investment side, you've got the startup side, you've also got the enterprise side experience. Walk us through your background a little bit. Kind of what were the things that shaped you as you got into your career that put you in the position you're in today?
Alan LeFort: You know, I, I would say the thing that put me into the position that I am today is just deep curiosity and a desire to learn about so many random things. And so, you know, I have an amazing resume. None of it was planned. But when you're prepared, interesting opportunities pop up and you're just like, "I could do that. That would be fun. That would be interesting." And so whenever an opportunity come up in my career, I would always ask myself, "What is the, what are the odds that I had sought this out if it would have got in front of me?"
[Alan's Unique Career Journey]
"And what are the odds this would ever be in front of me again?" And if the answer was "Probably not highly likely," I should probably do it. That's what landed me to live a couple years in the Czech Republic. It was a unique opportunity. And I'm like, "This isn't going to come up again. Off we go to Europe."
But going back to my career, I started uh, studying both computer science and business in a joint degree up in Canada. I eventually focused more on the computer science side for a bit. Then eventually I went back to school and got a, a bachelor's degree in, in uh, in business administration, but with minors in theology and um, philosophy. So general arts kind of school. But I think that in itself gave me this view that it's better to be a deep generalist than a specialist. And so I just set aside time to be good at user design, time to understand the psychology of people that use software, time to understand how software is built, how software is sold. And I put myself in different roles that would allow me to learn that.
So I've been a Director of Support, a Director of SEs, a Director of Sales, a VP of Product Management. Uh, I've been GM at a couple places. Rather than specialize, I've always sought to wrap my arms around all the different pieces of a business that, I think as my career has evolved, it's allowed me to have a really deep understanding of the cause and effect of business. How one metric over here affects one over there, how a decision made here has downstream implications here. And so I never really chased titles. I just chased understanding.
Jake Aaron Villarreal: Yeah. Wow. That's amazing. Well, you've had some great career. If you haven't had a chance, go to Alan's LinkedIn. He's got a nice career path of where he started and how he's moved up in organizations. And you know, what was interesting to me is that at one point you were running a $200 million business um, you know, reporting to the CEO, and, and you decided to walk away from that and join a startup. You know, kind of walk us through that decision because not everyone makes that choice of taking, you know, some might call golden handcuffs to, to leave, to jump into, you know, another company that's really from the ground up building and there's a lot of risk. There's also a lot of opportunities.
Alan LeFort: Yeah. I think in my case it was very much of like, what excites you? You know, it t-, sometimes it can take a long time to figure out who you are. You know, maybe it took me 'til my 50s, but I realized that my passion was in innovation and building. And that happens way more in small companies than it does in big companies. You know, I, I would say innovation is a feature of a large organization. In a small organization, it's the lifeblood. It's the reason for being. And so, it just aligned better with who I, I was. Also, to be fair, you know, when you get deeper into your career, you tend to be a little bit more financially well off, so that you can focus on passion over profit. And I was just in that lucky and fortunate space where I could do that.
Jake Aaron Villarreal: Yeah. Well, it's funny you bring up the, the year 50. I'm in my 50s myself currently. And you know, when you're young, you have the energy to do whatever you want and you could succeed, you could fail, you can learn, you could keep going on. You get older, you have to make different decisions uh, and you decide to take more risk or take less...
[The Decision to Join a Startup]
...risk. But you brought up an interesting point. You, you said that you felt that startups were actually better led by kids in their 20s or people in their 50s. Walk me through your belief there on that.
Alan LeFort: Well, I, I don't know. I, I wouldn't necessarily say better led, but I do think that the founders have the ability to go all in. I think it's really hard, there is no nine-to-five startup. So, the question is, what do you have going on in your life, your obligations socially, financially, etc., that would allow you or not allow you to go all in on something because you have belief and you have passion? I just empty nested. You know, my oldest is now in university... my sorry, my youngest is in university. My oldest is, is, is working as a product designer at this really cool startup called Solid Core. Give it a little plug. And, and so now, you know, they visit and they come by, but I don't spend the same amount of time on my family care and feeding so I can put a little more time into um, into my business, right? So, I think it's just, do you have the time and the bandwidth to go all in? I think it's easier when you're in your 20s, you're out of school, you don't have... you're not encumbered. And in your 50s, you're magically not encumbered. And you're seeking purpose again because your purpose was your kids and now they're gone. And so, in terms of your everyday life, right? So I, I almost think it, it's um, it just times well where you can match the needs of a startup with the time you have to put in and the mental space you need for it.
Jake Aaron Villarreal: Yeah, makes sense. You know, as you look at the market today, and we'll jump a little bit, transition here into the business. You know, you look at AI and it's transforming everything we do from marketing to outreach to operations...
[The Role of Age in Startup Leadership]
...customer support, sales. It's, it's really coming into play in all areas of a business, and quite frankly all industries as, as, as we look at that. You know, there's positives and negatives. Talk a little bit about what inspired Strongest Layer to build what you guys are building. Explain what that is, and then why it's important.
Alan LeFort: Yeah, sure. So, I've been in the email and generally the cybersecurity space all my career. So, I've always had that focus. The company I came out of, Proofpoint, predominantly made its name in email security. So the idea that when you get an email and it has links and it has attachments, should you open those, should you click on them, can software help you determine if that's a safe email to click on or not, or, and a safe attachment to open or not? So, and you know, I think for me, when I think about the importance and what businesses run on: their intellectual property. Let's face it, our, our file storage is our inbox. Our communication is our inbox. Our intellectual property sits in our inbox. What is more important for an organization to feel protected than that, that body of, of information?
And so, when AI came, I explored a lot what AI could do as part of my role. You mentioned I, I, you know, I've been involved with the investment community as a, a, a venture partner and limited partner in a couple funds. I would spend a lot of time with startups and I would sometimes advise them. So this 2024, I spent time going into go-to-market, just helping them figure out go-to-market just as an adviser to stay in the game while I was taking my year off. And I dug into AI go-to-market. And after only a couple weeks of digging in, I realized, "Oh boy, this is going to break email." And I'll tell you why. Because the way we spot bad emails is we look for...
[AI's Impact on Business and Email Security]
...obvious flaws. There's a typo in the domain. This is not proper English. It looks like it was written by someone who, it's not their first language. The images are crude approximations of a brand. Right? And so when I was looking at this go-to-market stuff, it was like, "Give me your face, record a couple minutes of your voice, and we will simulate the rest and no one can tell the difference." I mean, kind of the promise. And as I dug into it, I thought, I had this revelation: these are the same techniques that hackers are using now. There's a convergence, right?
So, a hacker would go and find a known brand, then try and find an interesting, compelling offer with urgency to get you to click on a malicious link or, or open an attachment that seems innocuous, but you could always spot the spelling mistakes, spot the obvious things. With AI, they're gone. And if they was doing it on marketing campaigns, I'm like, it's obvious that attackers are going to do the same. And employees at companies won't be able to spot the difference. And so, you know, I think it, it went from being kind of an exercise of, how do you spot Where's Waldo, you know, to how do you walk into a museum and pick out the one forgery that fooled everyone? And, and nobody can do that, right? So, I had this sense that AI is going to break email security, but it can also be the solution. And so, that's when I started getting passion for the idea um, and, and decided I wanted to get back in the game and do something.
Jake Aaron Villarreal: Yeah. Well, you know, big enterprise companies for a long time have had security leaders, security administrators that are trying to stop this from happening a long time. And they've bought many tools, technologies, systems to counter the attacks that have happened. When you go into a company that's already got the infrastructure set up, what are you giving them that they don't currently have?
Alan LeFort: Yeah, absolutely. So, listen, the email security industry is very mature. It's been around for 20 years plus. So they all have tools. They all have tools in place. What they're struggling with is the effectiveness of their tools. So the way... little primer course on email security, won't get technical, promise... but basically the way most security products have traditionally been architected is the same way we, and it's all inspired by the medical profession. Like, how do you stop... and public health. How do you stop a virus from going crazy? Well, you need to understand how it works and then you need to create a vaccine that protects the body so that when it hits them, it doesn't react in a, in a very uh, you know, in a bad way. And the underlying phenomenon is you need to study those who are infected to find common patterns to then create the vaccine.
Security is the same. We, we see bad attacks out there. We look at the logs. We analyze the software. We try and figure out what it's doing. We find some common characteristics so that we could detect it quickly and, and we can block it when we see it. Often that'll be called a signature or a rule or a pattern. And it works really well when attackers take one type of attack and just send it to a thousand people. One pattern blocks a thousand attacks. But what happens when the attackers use AI and say, "Here's what I'd like to do. Now go and create 1,000 unique variants that are tailored to the thousand people that I'm trying to attack." What happens to the one signature to block them all? Now you need a signature for each individual attack. But if you've never seen it before, where does the signature come from? And that is the dilemma that more and more we're seeing in email security.
Jake Aaron Villarreal: So most companies have a couple...
[The Challenges of Email Security]
...approaches to selling their products. When they go in, they're selling a solution that either they don't have, that they know they might need, or it's a new category, you have to explain what it is first, educate them on what it can do differently, and then invest in a, in a potential solution that will help them in some way. You talked about displacement as a sales process, where they have products in place already, but you're doing it differently. What's that sales process like versus just a standard sales process?
Alan LeFort: Well, I think it's not just a process, a sales process part. I think it gets earlier into how you decide to build your product. And I would argue that, you mentioned new category creation, I think there's a good playbook for that. It's called product-market fit. It's called customer discovery. You get out, you interview lots of people, they tell you what they think they want, you go build that, you call that minimally viable product. There's a good playbook for that. What there isn't a great playbook around is when you're trying to disrupt an existing category. And so, you know, we came up with our own little framework for that internally. We call it the product gap framework.
And the, the, the idea is that in existing markets, people are trying to get jobs done and they're, in some cases, they're being done poorly. Meaning, they want the tool to do something for them and it's not quite hitting the mark. And so, we look for opportunities where the gap between what the company would like to do and what the product allows them to do is very large and it's very frustrating. And if we can create a 10X advantage on those metrics, then you have what's necessary to go in and get someone to change their behavior, to change their configuration, because people tend towards conservatism. "I already solved it. I already built it. It's working well enough. I don't want to revisit this." You have to give them a reason that they can't refuse. Right?
So for example, we've built this, and our sales motion follows is around, what metrics are we going to make hugely better for you? And we can name the ones that we've targeted. Number one, we have to detect those advanced attacks that AI are generating that others are missing, and we have to be able to prove that and make people feel that we're doing that in a way that's useful to them. The second one is the flip side of detecting everything is, when you get very aggressive, sometimes you detect things that are actually benign. That's called a false positive. And if that benign thing is a contract, it's an invoice, and it's goes away somewhere into limbo, call that quarantine, business gets interrupted. So false positives are a big challenge for organizations. And so we said, "Can we zero false positives?" And we set that out as a goal, and we have delivered on that, by the way. And the third one was employee productivity. Everyone says security is a business enabler, but it's kind of become a little bit of a tongue-in-cheek reference. No, I don't know that there's a lot of employees that believe that. I didn't when I was there as an employee in different companies. But we said...
[Disrupting Existing Categories in Sales]
..."Well, what would it take to really make it a business enabler? How do we get it out of the business of, you know, slowing down organizations in the name of security to providing better security and allowing employees to be more productive?" And that was our 10X bet on that metric. And obviously, I could talk forever on the features we've built. But it started with: what are those core metrics by which if we could provide 10X improvement in the way we approach things, in the way we do things? Then when you think about selling, imagine going and say, "Hey, the top three metrics are these things, and we 10X them in this way. Would you like a demo? Would you like a POC? We can back it up. We can show it to you." That's the core of what we've built.
Jake Aaron Villarreal: That's great. You know, when you think about it, there's a lot of data that's being transfer, transferred between emails every day. If you're the chief security officer for a company or maybe the founders of a big enterprise company, what are the things that you're most cautious about having exposed or being phished out of the company? Like, what are the, what are the top things that most, most hackers are trying to get from a company?
Alan LeFort: Well, you know, it varies, but I, I think the intent is typically, ultimately it's all financial, right? Like I, I think there might be a variant of some that are doing it for, you know, some political or other means, but generally speaking, it's financial, right? So ransomware is very popular because you need your data to operate, and we won't give it back to you unless you cut us a check. That's a very obvious one. Getting people to do wire fraud. So, wire it to another bank account that is not retrievable, not recovered. That's another, you know, that's another type of, of common fraud we see. We've seen even payroll scams where it's not even going after the company, but it's impersonating the company to get someone's paycheck sent somewhere else. So, I would say financial motive is, is, is the, is the largest one. I think there's secondary consequences to those attacks when they do happen, because it drives greater vigilance, maybe a little more scrutiny, maybe buttoning down of processes that tend to slow businesses down over time. And so, you know, I think their obvious goal is to get money out of you. The secondary effect is it puts your organization in a more, less trusting way. Uh, and that's unfortunate.
Jake Aaron Villarreal: Yeah. For the listeners out there that are just employees of a company, what are common things they should be looking out for in terms of opening their own email?
Alan LeFort: You know, first thing, I think there's lots of security awareness training out there. But the um, the best advice I would give, I got from watching a, a show in the UK that was all about con men. And um, fascinating show. I can't even remember the name of it, but I, I loved watching it. Well, one phrase that stuck with me, and it was talking about the art of doing a con job, and it said, "You can't con an honest man." And what that really meant though was, if you think of the flip side of that, is if it's too good to be true, it probably is. We are not in a world where people will give you $1,000 because you like something or that they'll send you a gift, you know, because of XYZ. Like, so if it is too good to be true, you should be skeptical. There's not a lot of free rides in the world. So, I would say just that healthy skepticism from a standpoint of like, "Does this make sense? Would someone be offering this to me? Would... and, and is this reasonable?" Is...
[Key Metrics for Email Security Success]
...it reasonable that my CEO would ask me to get an envelope of gift cards and drop them off at a post office box addressed to some PO box? Probably not, you know. So, I think the reasonable test, and, and the idea that if it's too good to be true, it probably is. Just those two rubrics will discard a lot of emails that you should probably just ignore.
Jake Aaron Villarreal: Yeah, it's funny. I just, last week I got an email from some random company that...
[Common Threats in Email Security]
...said that, you know, it was an invoice attached and it was, you know, you owe like $18,000 for coaching services, and you know, "please pay the invoice," and then there was a line. And under that line was, you know, "Match Relevant" which is our company, um, "pay um, accounting like department." Like as if it had come from a third party and then we had responded, and then it was kind of getting up to me as the founder now of like, "Hey, this hasn't been paid." If I'm a 5,000 employee company, that might just fall into the hands of someone in accounting. It looked like it came from someone in accounting and then was sent back by our founder to get approved, and "let's just pay this." I'm sure that happens a lot. But even at a smaller stage level company, you know, I was second-guessing, "Is this accurate or who is this company?" So, I actually had to go look online. "Okay, who is this company? Okay, go to LinkedIn. Who are the people?" And really dive in. And you know, it was all fraudulent. It looked like it was coming out of like, you know, Africa or something. And you know, at the end of the day, you know, it's happening all over the place. But yeah, I think it's kind of crazy. And it's not just with AI and emails, it's also, you know, voicemails and following up calls and all sorts of crazy stuff happening. So I, I love the space you're in.
Talk a little bit about the AI aspect of it, because you know, you're capturing a lot of data I'm assuming, and you have options to train it, your LLMs, to not train it. Like what's your philosophy? What's your process and how your product is architected and the data side of things?
Alan LeFort: Yeah, you know, I think the philosophies can vary depending on the business you're building. But we're in the security business, and, and I would say, and adjacent to that is the privacy business. So if we can read every employee's mailbox to protect it, there's a lot of information there that it gives us concern. And so many CISOs are concerned, "Wait, you're going to train your AI to protect us on all of our corporate secrets? That's a hard pass." We knew that would be the case, and we knew that would be the case for many years to come. So, we purposely chose an...
[Advice for Employees on Email Security]
...architecture that has no training of LLMs. We use off-the-shelf LLMs. And the way I, I, I like to think about it metaphorically is we treat it as a super software CPU. We feed it things, we ask it to give us, you know, verdicts, reason through things, but no training ever happens to an LLM using email data. We just said that is the line in the sand that we're drawing. We will always use it in this black box, not trained configuration.
And for a couple reasons. Number one reason, if you believe that it takes an, an AI to fight an AI because it's just that powerful, and you need a similar one to do that. There's an extra part of it, which is, it's not just AI versus AI. There are discoveries happening every year that are pushing the frontier of what these models can do. New types of models, new highly performant models. DeepSeek 3.2 just came out and it looks like it's already rivaling or exceeding ChatGPT-5. That part doesn't matter so much, but every 3 months, four months, we're going to see this announcement. So, let's say there's a 10X improvement in these LLM models and it comes out. Hackers grab it, they jailbreak it, they're using it. We're stuck on the one from two years ago because we trained, we spent all this money and time, so now they have something 10 times better than we do, but we trained, so we're stuck on ours for a little while. What does that mean for the people we're defending? There's an asymmetry there. There's 10 times more powerful. So, if we really want to keep up long-term, we have to have that same situational flexibility. They get the latest LLM, we get it, too, because we're in a fight, and a constant fight.
Jake Aaron Villarreal: Yeah, that makes sense. I like that strategy. Talk a little about the company. So, you joined, you're leading it, you're helping build this as the co-founder. What's um, what's the size of the organization today? How far are you into it? What are you seeing in terms of success?
Alan LeFort: Absolutely. So, we're going to be about 30 people by, by, you know, end of December. We just got a couple more hires uh, that we, that uh, that we did this month. Um you know, we're about 20 people in engineering that are, are led by our CTO in Pakistan and surrounding areas. We have the rest of our go-to-market that are split between the US and Canada. And you know, we are enjoying great success. I'd say we got our funding April 15th, and in six months we've, we've released our, you know, kind of a, a major platform uh, you know upgrade that is really resonating, that is really catching a lot of advanced threats. We are, you know, hoping to exit the year with, you know, quite a few, you know, you know, dozens of customers, everything goes right. And, and really go into 2026 scaling based on, on the product success. So you know, we're at that point where we think we, we have a...
[AI and Data Privacy in Security]
...great product and people are giving us great feedback. So now we're like, "Okay, it's time to get the word out. It's time to get people, get our product into people's hands and start protecting them, you know, a broader set of customers." And so we're just coming into that, "Okay, let's start, let's start our scaling path. Let's start acquiring customers," you know, which has been fun because we've got a great product and, and we're getting great feedback and, and we're, and we're learning really interesting things as we analyze the market. We're seeing, you know, just through these customers and prospects so much. So, we're, we're pretty excited about where we're entering into 2026. Um, and we have just even more innovation that's coming that, that's we think is going to be really helpful to security practitioners and preserving not just their security, but their own personal sanity as, as we try and, you know, lighten their, their workloads.
Jake Aaron Villarreal: Yeah, I like that. So, there's a lot of sanity going on out there and insanity going out there, too. Um, when you look at the company today as you look to scale it, what, what, what's the biggest challenge that you see as you go through your growth? And every company has challenges.
Alan LeFort: I actually, you know, there's all kinds of challenges. I'd say one that we've, we've been grappling with is, when is change management, right? So when you come up with a new way of doing things and people are used to and trained to the old way, even though the new way is better, it can be hard for them to let go of it. When you've defined your identity as, 'I do these tasks, I do these things.' And we're like, 'We have a new product that will make all those tasks go away.' There's a bit of resistance. You don't know the product's going to work, so you got to test it out. But it's also like, what does that mean for your role? What does that mean of like, what your new day job looks like? If you didn't have all this minutiae to care for and, and, and take care of, now, what do you do with your day? Right? So, we spent a lot of time thinking about, we've improved all these metrics, but now we're giving them back free time. What new features can we build to let them use that free time in a more strategic and less tactical way? And so I think that was one of our learnings is, you have to, you know, have to give them a pathway to ease into that new reality of the way you do things. And I think that's true in AI in general. I think a lot of organizations are, are struggling with, there's a clearly superior technical answer, but there's an organizational fit that has to be figured out.
Jake Aaron Villarreal: Yeah. Yeah. We're seeing that uh across the board and change management is such a big deal. There's actually some pretty good companies we've uh interviewed that that's all they focus on, and it's because AI is, you know, helping and also changing how people operate their business, and that becomes a personal situation for a lot of employees too. What other values do you bring to the company? And one thing seems to be pretty clear. If you're not taking advantage of the tooling of AI and learning about how it works, you're probably not going to be a preferred...
[StrongLayer's Growth and Future Plans]
...employee. So there's some real advantages to understanding what AI does or maybe changes, you know, a company and roles within that company, but also the mindset that you should be as an employee understanding how you can be better educated around those tools and, and get up to speed. And also be able to continue to discover how you can operate differently with this transformation of AI across the board. So we're seeing that really pretty clearly right now. You know, if you look at the industry that you're in today and let's fast forward 5 years from now, if you execute at the highest level that you think you can, what does email security look like then?
Alan LeFort: You know, I think, I don't think it's one of those things that ever gets solved, right? Like at its core, the motive, the intent, 'I want to get money in a way that, you know, is not legal.' I don't think we've stamped that out. And what are we at 10,000 years into humanity and it's still a thing? I don't know that we're ever going to remove the, the, the criminal element, the profit motive. Um, and I think it'll always just be a continuous game of 'we found a new attempt to get in, you blocked it. We found a new one, you blocked it.' Only when it becomes just so cost prohibitive to use email as a way to breach an organization, they'll shift to other methods.
But, you know, we don't think of what we're building as 'we want to secure email.' That's our entry point. We want to secure communications wherever there's words and those words can be weaponized, misconstrued, etc., in order to achieve, you know, illicit gain. We think we have a technology that can help with that. So whether it starts in email but eventually it migrates to Teams and Slack or some other communication method, um, you know, we, we want to make sure that we're there to provide what we do as it moves because they're not going to go away. They're just going to try something different. Front door's locked, go through the window. It's that simple, right? So, we just have to be prepared to anticipate...
[Navigating Change Management in Growth]
...where they think they're going to go and make sure that our customers have that protection when they get there.
Jake Aaron Villarreal: Yeah. Makes a ton of sense because yeah, there's a lot of companies that email you can use internally, but also, you know, Slack is like predominant in startups and even bigger companies where they, that's really where everyone's communicating. So if you get something or someone, it kind of slides into your Slack infrastructure, you know, are you giving away information of somebody that you think you know but you don't? Like yeah, I could see where security across the board like in, in every communication channel would be uh a good thing to have.
Alan LeFort: Well, and I think, you know, what we consider a, a security risk versus a compliance risk. It's just classes of information. So, you know, will they, will, where there'll be a slew of attacks where they're coming in through Slack and they're hitting, you know, strangers are coming at your employees. I think that's kind of buttoned down a bit, but is it possible that, you know, you're in a large company and you've got a hundred companies that you do, that are third parties you're doing business with, and it's so easy to drag and drop and say, 'I don't have time. Here's a list of those customers,' but those customers were not the ones that you're allowed to send over because you're not authorized to share that data with a third party. That's a compliance violation. But it's so easy to just drag and drop it in Slack, right? So those could be other types of things that we do to help people get all the benefits of all this communication and connectiveness, but provide the guardrails that ensure that we're doing what we ought to do.
Jake Aaron Villarreal: Yeah. Well, this has been a great topic. You know, one last question I have uh around this whole space is if you do get attacked and you do share information and you do get someone asking for ransom, is there a good solution of how to get out of that? Is there like an internet police? Is there a way to counter a threat? They have your information. They have your data. They're asking for millions of dollars. Where do you go, or are you just kind of placing a bet that you should pay them and they won't release the data?
Alan LeFort: Yeah, you know, I think, I think this is a, a very, it's a, it's a great question because I think, you know, it's... and I, I've never been in the shoes of someone who's had to deal with it at a corporate level, but the idea that for example, you know, if you're an administrator hospital and you've had ransomware happen, it's very easy for the security professionals to get on their high horse and say, "Do not pay the ransom." But if what's being held up is your ability to provide critical care, that's a tough trade-off, right? So now, if you're a consumer and they're like, "Hey, we've, we've stolen, we've got your Facebook account, and if you want it back, it's $1,000." That's probably not a good idea because they're just going to keep coming back and doing it to you over and over again, right?
And so like, you know, the question there is, 'Okay, well, depending on the service that's involved, they have teams for this. They have security teams. They have...' If, if it's more generalized, I you know, a lot of law enforcement is set up as a first point of contact to help you with that. And I think a lot of times the reasons people don't go to the authorities is not fear of the attacker, it's shame of disclosing that they've been, they've been had. It's kind of, it's embarrassing to say that you've been conned.
[The Future of Email Security]
Jake Aaron Villarreal: Yeah.
Alan LeFort: So I think part of it is getting past like there's no... it can happen to anyone. It can happen to the most advanced technical people. You're not dumb because it happened to you. And so I think getting past that and just saying, 'Put that aside. Let's go and get the right help and get the people that know how to deal with this, that have a playbook,' because you were dealing with the criminal element. Who thinks it's a good idea to try and engage with them on their own?
Jake Aaron Villarreal: Yeah, good point. Well, that's really good food for thought and excited to see where things go for you, Alan, and your company, Strongest Layer. We're heading into 2026. What's on the road map? What are you excited about?
Alan LeFort: I am excited. You know, I would say I'm concerned of 2026 because I think we're just in the early days of this AI enabling attackers. We actually did some research and we found that currently we estimate about 45% of the attacks that we have stopped were AI generated. So, we have algorithms to sort of figure that out. We're forecasting it's probably going to be 60 to 70% by the end of 2026 and almost fully 100% at the end of 2027. So, what do you think that's going to do for the amount of stuff that gets through, for the am-, for the volume of scams that are, are that going to hit folks?
So, you know, we don't love that, but we do love the fact that we can help organizations with that. It's giving us, you know, it's our reason for being. It's what we do best. So, I don't want, ever want to say that I'm excited that there is more attacks. Um, I'm really concerned about that, but it's also validating that we've built the architecture for the time that is here and the time that is coming.
Jake Aaron Villarreal: Yeah, that's amazing. I, I like that. Yeah, you've got the solution that can cure hopefully the bad that's out there, the bad actors, and excited to see where it goes. Alan, if anyone wants to find you or find Strongest Layer, where do they go?
Alan LeFort: Well, uh, simple. You can find me on LinkedIn. I'm easy to find. Alan LeFort. Um, you can go to strongestlayer.com and, uh, and you know, and, and if in a pinch, you can also do a Google search.
Jake Aaron Villarreal: I like it. Very cool. Well, I want to thank you for coming on here today, Alan. It's been a pleasure talking to you again and for the listeners for listening today. It means a lot. You spent your time with us. I'm your host, Jake Villarreal, signing off for now, but can't wait to catch up with you all on the next episode. Until then, Alan, the world, take care. If you like what we're doing, don't forget to subscribe, leave a review on Apple Podcast or wherever you listen, and follow us on YouTube where we go behind the scenes to learn what it takes to be a startup founder.