Jake Aaron Villarreal: I'm Jake Aaron Villarreal, born and raised in Silicon Valley here to take you behind the scenes to share what it's like to be a startup founder. The journey they're on, problems they face, the products they build in an effort to make our lives better. I'm excited to have with us today Ambuj Kumar, co-founder and CEO of Symbian. Ambuj, welcome to the show.
Ambuj Kumar: Happy to be here, Jake.
Jake Aaron Villarreal: Well, happy to have you. A little bit more about Ambuj, he leads Symbian, a company using autonomous AI agents to transform cybersecurity. He holds a bachelor in technology from IIT, one of India's top engineering institutions, and an MS from Stanford. With over 100 patents in chip design, cryptography, and security, a former NVIDIA engineer and co-founder of Fortanix, Ambuj is now focused on solving the cybersecurity talent gap and alert fatigue. At Symbian, his team delivers fast, scalable protection with AI agents that act as virtual security analysts. Well, excited to have you here today. Where are you joining us from?
Ambuj Kumar: I'm here in Northern California, Bay Area.
Jake Aaron Villarreal: Very cool. Born and raised. I love the area. I think proximity is power. From investors to talent to everything everywhere in between. Where are you from originally?
Ambuj Kumar: So I grew up in Bihar. It's one of the rural areas in India. So 50 miles away from the nearest electricity pole, as I like to describe it. But got a good education there, and here I am.
Jake Aaron Villarreal: Really cool. Well, I know this isn't your first startup, but walk us through, take us through a little bit of your origin story and what early experiences helped shape you to become who you are today.
Ambuj Kumar: Yeah. So, as I said, I grew up in India, in one of the most remote places there. So as such, right, you have to be a little bit motivated to make it work. But I had access to books and early on since I didn't have anything else to do, I became self-taught. And I saw that that helped me do well in schools and that eventually shaped me to be somebody who was self-reliant and making the most out of the environment. And I realized that that is key to success even at a larger scale.
So one thing led to another and I found myself at IIT Kanpur, which was the number one engineering college in India. And I got exposed to India's best students and I learned from them a lot. They were much better than me in every single aspect, but over four years I started to see how they studied and learning from them, you know, I became the number one student in my class, graduated top of my class. Then NVIDIA recruited me, back then a small company, but of course they were an incredibly well-run company, very smart people. They had really interesting problems. So I was torn between coming to the US for doing my master's or taking a full-time job. But NVIDIA had this really nice package where you could do your master's from Stanford part-time while working full-time at NVIDIA. So I was like, "Okay, I'm getting the best of both worlds." So that's the path I took.
And again, as I migrated from being, you know, a good student to being a professional, I got exposed to lots of incredibly smart people at NVIDIA. And but true to my nature, I learned from them, you know, started to get better. And after eight years when I left NVIDIA, I was a lead engineer, I had probably filed 30, 40 patents there, leading their memory controller, so a bunch of good things. And similarly joined a startup, did really well there, became chief architect of cryptography researching, an unfunded company, got sold for $50 million.
And then started my own company, so as an entrepreneur did a bunch of things there and, you know, grew that company to hundreds of enterprise customers, raised $150 million and $135 million, and you know, a great outcome. And now, you know, putting all the efforts in my next company, which is Symbian, which is taking security to the next level, which is that can you provide the world's best talent, virtual talent that is, to every single organization? And we see in the news that bad guys are coming after hospitals and schools and water supply and this and that. And our job is to build an AI system that will safeguard everything from bad guys. So yeah, that's my story.
Jake Aaron Villarreal: Yeah, really good. There's a lot in there. I mean, I guess the one that I'd just like to ask before we jump into your current company is, you know, NVIDIA was a great company then and it's obviously an incredible company today and seems like it's the foundation where everything's coming from in terms of technology and AI and people. What's the one thing that you learned from NVIDIA that really has helped you in shaping the companies you've built and are currently building today?
Ambuj Kumar: Yeah, I say it's intellectual honesty. So what does it mean? It means that you call out things as is. You don't sugarcoat each other. You know, if you see something good, you acknowledge it. If you see your competition better than you, you acknowledge and learn from it. If, you know, you see somebody not using correct data and just trying to, you know, create lots of internal processes, you call it out. And you create a culture where even the most junior people in your company are not afraid to call out the most senior people in the company, and conversely you promote the right set of people, people who exhibit your intellectual honesty.
Is that, and it works like magic because if truth is the cornerstone of your culture and you are dealing with customer's reality and taking real feedback and improving like, you know, .1% daily, and you compound that over 10 years, it becomes a company that goes from you know 10 billion or 350 million market cap when I joined NVIDIA, now to a $4 trillion market cap. So to achieve anything great in life you have to be consistent and you know improve almost daily. And what I learned at NVIDIA was that intellectual honesty was the cornerstone of their culture. And so that is something I, you know, I try to exhibit in my own companies now.
Jake Aaron Villarreal: Yeah, that's great. You know, I worked at a big company too, Oracle, and back in the day, you know, it was transforming you know the internet. And really when the internet was evolving, they were a big player and the infrastructure behind dotcoms and you know, Amazon and all these big companies were building on top of Oracle databases or that's where their data was stored. And now fast forward 25 years later and you see big companies that have evolved and you know reinvented themselves and are big players in the space again, which is really cool to see. Um, you know, you are building in the cybersecurity space. What was it that you saw there that you felt like there is a way to innovate, you know, a new solution there with AI that you hadn't seen before?
Ambuj Kumar: Yeah, good question. So cybersecurity, as you know, is a very, very crowded field. And the reason for that is that new types of attacks come and by definition they target, you know, gaps. So if you've got like endpoint security and got network security really well, they will try to attack you on identity. You fix your identity, then they will start to compromise your browsers. If you fix your browsers, then they will start to compromise your right... So security is always finding about finding new problems and protecting from that. And as such, it is very operations heavy because it's always evolving. So you need to constantly change your processes, figure out tools, operate them, etc.
And there are like, it's funny, right, like guess how many people work in cybersecurity worldwide? Just take a guess.
Jake Aaron Villarreal: 5 million, I don't know.
Ambuj Kumar: Yeah, I mean, that's about right, you know, 8 million. But if you see that the world has 8 billion people, right, and we have 8 million people working in cyber, that means you have one person protecting the digital space of like you know a thousand people. So one cop for a thousand citizens, right? Digital cop that is. So of course that's not enough. And what happens is that if you are a large company, of course you have lots of problems, but you can at least try to afford or try to recruit some people. But for most of the, most of other customers, they don't even know where to start. And people are always bombarded with lots of things to do in cyber and they don't have, they don't have expertise, they don't have talent, they don't have money, they don't have tools. So it's always you know trying to do more with less resources.
Cyber is something that's not, you know, entertainment, right? It's not that if you don't do well, you get to correct it like next year. If you don't do well, somebody will come and do bad things with your organization. So you cannot take a chance. And so what I saw was that, can we use large language models to create a virtual employee, a virtual cybersecurity employee that can do, maybe in the beginning 30%, 40%, 50% of what a typical cybersecurity person does, but over time, can it do even more? And so, so this is what we are building. We are building a digital, virtual cybersecurity employee that can operate all your tools, can take care of all your security policies, can go do more, can go do more both proactive as well as reactive security. So it knows what's good for you, it will go and configure your tools accordingly. And if your tools find something suspicious, it will know whether that activity is real or not. And if it's real, then what does it mean? Maybe it needs to go and isolate some endpoints. Maybe it needs to go block a firewall port. Maybe it needs to go inform somebody that they need to take some corrective action. So all of these things our AI agents do. So this is what we are building.
Jake Aaron Villarreal: Was there an aha moment where you built it and then actually saw it work and you thought, "Wow, this is something that not only does the job, but it does it way better, way faster, way more accurate than a human." And like, when was that?
Ambuj Kumar: Yeah, that's a great question. So what we did was we created our first agent, which is an AI SOC, which is essentially, you know, security operations center. And so, so it's a digital equivalence of a SOC analyst. And so we created our product and we wanted to see, you know, how it fares in real life compared to a human. So we did a competition in April where we put $10,000 on prize and the challenge was for humans to come and find 100 threats that were there in the environment. And whoever could find all the threats with, you know, like, in the most efficient manner, they will get the most points and will collect prizes. And it was a big success, so much so that our systems crashed and we had to extend the competition from 24 hours to 36 hours, etc. But the shocking result was that only 5% of participants could do better than our AI SOC agent. So if you get like 100 motivated SOC analysts and you put like, you know, Symbian's AI SOC agent, it ranks 95th percentile. And so that was a big eye-opener for us because we were certainly hoping that, or expecting it to do better, but we didn't expect it to be this good.
Jake Aaron Villarreal: Wow. Does it actually replace a security analyst? Like at the end of the day, when you're talking about talent in cybersecurity, and we know they're expensive and they're hard to find and you got to make sure they can actually do the work. But you know, there's a lot of talk about what AI, what AI agents can do, what they can't do, like walk us through that.
Ambuj Kumar: Yeah, that's a good question. Um, using like a car analogy, cars have not replaced, you know, our legs. We still walk once we are in our house and cars don't operate. But you know, it will be stupid for us to, you know, go 100 miles walking, right? So same thing, humans are very precious, very, very precious. And it's like, in the future, and this is like near-term future, I'm not talking about 10, 20, 30 years, I'm talking maybe 2 years, 3 years that kind of time frame. I believe that every one of, like every one employee who is working in cybersecurity, they will have like this super assistance from Symbian. And it's like you have your personal army protecting you and you are commander-in-chief, right? So you, you know, they will do most of the work for you, right? They can even suggest to you what needs to be done. And if you have better judgment, you can override them, but not, you can follow them. And wherever they have gaps, you know, you come and fill it.
So, so just like cars, right? You walk from your house to your car, you take your car to the destination, and then you do like, you know, the last few feet of walking. And so it will be similar. It's not so much as replacing an analyst. Um, I mean calculators have not replaced, um, you know, business people, right? It elevated them. And the same thing here. Our AI SOC agent will elevate you to do bigger things because there is no dearth of security tasks. But it will be really, really inefficient if you try to do something manually that a SOC agent can do at a fraction of the cost, um, at, you know, better, with a better result because it will memorize more things. It has visibility in more things, rather than like, you know, rather than competing with machines, rather than competing with AI. I tell people to use AI to your benefit because AI is there to work for you.
Jake Aaron Villarreal: Yeah, well said. You know, you talked about different threats attacking a business or an enterprise. Given the rapid evolution of cybersecurity threats, how does Symbian ensure that agents stay relevant and adapt to new attack vectors and vulnerabilities?
Ambuj Kumar: No, that's, that's a great point. Just recently there's a zero-day vulnerability on SharePoint that is, you know, taken things by storm. But the incredible thing with Symbian is that we monitor everything. So we monitor any mention of new threats that come on the internet. We also curate some of these things and do it manually. And we also subscribe to lots of different things. So for example, we use MITRE, and MITRE publishes different, you know, tactics. And so we see them, and the way we are building our AI agent is that it has a very robust understanding of what security is. So it knows that if somebody takes your data, that is a bad thing. But how do they take your data? That is very tactical, right? Sometimes people trick you into clicking something. Sometimes, you know, they will put a fake website and sometimes, you know, they will run a process that will look benign to you, but it's really malicious. And all that thing, all those tactics, our agents continuously learn. And it's no different from a human who has been doing security for 10 years, but they also continuously learn from the internet and subscribe to different things and go check out, you know, thread feeds. So we are kind of mirroring exactly the same pattern for our AI agents. So it's built in a way where it has very strong foundational learnings of cybersecurity, but all the tactical information it's constantly being updated, like, you know, every minute.
Jake Aaron Villarreal: Yeah, that's really cool. There's so much conversation going on about AI agents and how to build them and, you know, quick outcomes you can get from them. How long has it taken you to build your platform? Uh, because you look online, you see demonstrations of "I can build an AI agent in like 25 minutes," or "You know, in two hours you're going to have an agent that's up and functioning and assists you in doing XYZ." But cybersecurity is a little bit different, more complex, more niche. Like, walk us through how long you guys have been around and funding and team size, like how big are you today?
Ambuj Kumar: No, those are all good questions. AI makes it incredibly easy for somebody to put up a demo. So, not even like 25 minutes. I think you can create a great demo in two and a half minutes. But the converse is that taking something that's working at demo and putting it in production is, you know, just that much harder. It's harder because you got to your demo really quickly. So there are lots of pitfalls that you don't fully recognize, and the thing that you are trying to do is also much harder. So you are behind and you are trying to go to something that is even further than what you anticipated. So it takes longer. So AI has done both. And we see this on a daily basis. It has made it easy for you to build a demo but harder to go from demo to production.
And case in point, right, Symbian, we were founded two years, almost two years ago. And right now we have more than 40 people, a really incredible, you know, technical team. We have more than 10 patents pending. Our founding teams, they have done foundational work on both AI and security. So we did like lots of things, but, and there are probably maybe three, four dozen companies who are trying to build AI agents for cybersecurity. But when it comes to production, very few have customers using them in production. Symbian is one of them. Some of our announced, you know, customers include Infosys, Wipro, Matillion, Axelerant Shields, and so these companies use Symbian in production.
I say that if something takes like, let's say, you know, 10 minutes or 15 minutes or one hour to do with AI, that's great. You know, that becomes your starting point. But that's a level playing field, right? If you have your AI, your competition also has AI. Now, the things that you need to do should be on top of that, right? And so in our case, that means, you know, like building accuracy. I mean, cybersecurity is not a field where you can make lots of mistakes. If you try to investigate an alert and, you know, if it was a true alert, real threat, and you mischaracterize it as, you know, a false positive, I mean there is real danger there. So how do you ensure that it is accurate and it's precise and the responses it's taking are also, you know, correct? There is lots of sophisticated engineering involved, which is, which is no different, right? Like anything great in the world never happened without putting lots of great effort.
Jake Aaron Villarreal: Yeah, I can imagine. I mean specifically in cybersecurity, like you can't get it wrong because that's the one time that, you know, you put a company out of business potentially. So you got to get it right. If they're going to use technology that you're building for them, there's so much investment in cybersecurity and chief security officers that are building teams. And we've helped build teams for you know, security officers in fintech companies and financial services, and you know, it takes a lot of people to manage the threats that potentially could, you know, hurt a company. How easy is it, or what's the timeline to implement your product? If a company wanted to try it, like what's that look like?
Ambuj Kumar: Good question. So all we need is API-level integration with your security tools. And so right now we have integration with more than 80 different security tools. So if you're using CrowdStrike, you know CrowdStrike EDR, as well as Next-Gen Splunk, SentinelOne, Microsoft Sentinel, Microsoft Defender, anything, almost all top-tier security products, we integrate with them. And so all we need for you to start to use Symbian is API-level integration with your tools. And then it starts to do its magic. So depending on, um, depending on like, you know, if you have all the credentials and endpoints and you know like URLs ready, it can be up and running in like less than two hours. It's really fast. It's really fast because we have put lots of effort into making sure that it's, you know, fast onboarding.
Jake Aaron Villarreal: Yeah, that's really fast. Incredible. What's the business model? Is it a subscription model? Is it like, what's a company getting into when they say, "We want to use Symbian, we want to try Symbian"?
Ambuj Kumar: Yeah, I mean, you know, like just to close the loop on that right, it's really fast that it takes two hours, but if you think about it, it should not even take like two seconds. I consider us as, you know, fast when you click just one button on Symbian, you give it permissions, and using your permissions, it goes and discovers what security tools you have. It goes and automatically integrates with them. It figures out your data model, data structure. All you have to do is, you know, click a button like, you know, "Allow All," that you do when you install your application on your phone. And we can do that. There is nothing getting in our way from achieving it. It's just that, you know, we have not built all the code needed for it. So two hours is, you know, fast, but we can, we can make it almost, you know, zero, zero time. I mean, those are things that we are working collectively.
Jake Aaron Villarreal: That's music to the ears of anyone on the inside knowing that they might have to integrate or implement or bring in consultants for weeks or months to get something up and running and then you hope it actually delivers. The fact you can do it in two hours and then start to see outcomes or, you know, the value it can provide. I think that's phenomenal. In terms of the model itself, is it subscription-based, or how do you make money?
Ambuj Kumar: Yeah, it is consumption-based. So we, you know, based on the number of alerts your security tools generate, um, we price our product based on that. And you take our product and it automatically takes care of all the tasks for you. So it's based on the number of tasks that you send our way. And what are these tasks? These tasks could be alerts and notifications, but in other cases, it could be the number of vulnerability fixes or the number of pen tests it does for you, the number of assets you have. So it's some measure of the amount of work that our agents do for you.
Jake Aaron Villarreal: Yeah, because in today's world like you have compute time and you got costs as a company that you have to make sure that you're managing effectively. You don't want to be upside down in your business model where you know you price out a product at a certain amount and then pretty soon you know they're using it more than you thought. And the next thing you know, you're, you know, trying to figure out are you going to stay in business. So I like that, especially when you're talking about agents. Really fascinating. You know, as you look at that space, you know, and as you continue to grow your company, oftentimes when you talk about security issues, it's after the fact. You already have been, you know, threatened and now you have an issue. Like what does your system do then? Like, say it's a company that comes to you and says, "We just got hacked or a virus got into our databases or whatever." Can you go in and help them after they've been attacked and now they're, you know, I don't know, maybe being asked to give money to get whatever goes on in that world? Or is it really just on the upfront before any issues happen, before you get penetrated, that you know that's where you play?
Ambuj Kumar: No, that's a great question. Our goal is that anything that humans can do, our agents will do, and our goal should be to do better than humans. And what you are describing is called a threat hunt. And so our threat hunt agent does exactly that. Let's say that you have a hunch, you feel that one of your systems has been compromised by a group targeting your enterprise, right? And so Symbian right, based on just that, it will figure out what is the modus operandi of that group, right? How they infiltrate your system. And then it will create queries, right? That if your system, if the particular system were to be compromised, you know, like how it would look. And then it will go and check for that hypothesis. If it finds a data point or evidence supporting that hypothesis, then it will say that, "Oh, looks like your system got compromised. Maybe I'll take the next step. If that system was compromised, what would the threat actor do next? Maybe they will pivot into some other systems. Maybe they will start some..." Look for that activity and so on, so forth. And so the idea is that just based on your hunch, it will go and do these things and then it will say that, "Oh, looks like you are compromised," right? And then it gets into digital forensics and um, so our goal is very much that anything related to security operations, which is, you know, the field of operating security tools for achieving any business goals, Symbian will do that, not just superficial soft analysis.
Jake Aaron Villarreal: Yeah. What's the biggest challenge for the company today? You're two years into it. You have a fair amount of people you're building. You got product. Sounds like you got good clients, big enterprise clients. Infosys and you know, Wipro, and those are, you know, hundreds of thousands of employees, lots of systems. What's the challenge for the company today?
Ambuj Kumar: I mean, the challenge for us is, you know, there are only 24 hours in a day and, you know, our aspirations are big. I think AI is a big, big turning point and lots of industries will disappear because of AI. And conversely, lots of new industries will appear. Lots of businesses will get reinvented. And this is a time to do something original and create a massive company. And so our goal is that what can we do today in 2025 that makes us, you know, in 2050, the next NVIDIA. You know, will be a trillion dollar, 10 trillion, or who knows what. And so we have big aspirations. And that, you know, responsibilities come in dreams, as they say. That means, you know, we are not only taking care of our existing customers and trying to find and sell to the next 10, 20, 100 customers, but also figuring out, you know, what should be our next product and next product and how all these things work together.
Um, if I were to stand in front of like 100 Fortune CISOs two years from now, right? What can I tell them that, "Hey, this is what Symbian has built?" Because what needs to happen today is clear to everybody because everybody has, you know, access to some information. But I think where large companies will get built, if we can simulate what will happen over the next two years and where the ball is going, and position ourselves to take full advantage of that. So, you know, that's our challenge and opportunity.
Jake Aaron Villarreal: Yeah. Well, maybe you will be the next NVIDIA. You never know. I mean, you were there for eight years, so you got a lot of insight and intel about how they operate. And it sounds like you're operating a great company today. You know, as you look forward, you know, we're halfway, a little past, you know, halfway mark in 2025. What are you excited about? What's on the roadmap? You've got agents that are in your platform, you deploy within an organization. What are you excited about over the next 6, 12 months?
Ambuj Kumar: Yeah, so um, lots of exciting things. I mean, our AI SOC agent is fully GA. Um, like we can, any work that your SOC level 1, level 2 analysts do, we fully automate it, and even like some of your level 3 work. And we'll continue to do more and more with our SOC agent. But very exciting, very shortly we'll also launch our threat agent, which is that it will work off hypotheses and go validate, both proactively and reactively, the presence of certain activities. And that is considered a very high skill. And if the security industry has a shortage of talent, hunters are kind of even more scarce. So our goal is that we can build threat hunters that will go and hunt for lots of threats in your environment. So that is something we are very excited about.
And then we have other agents coming as the year unfolds. And our goal is that we can learn everything about your organization, just like an employee who joins your company. And by learning, right, it will not ask you questions that it can figure out on itself, nor it will try to create something that you will dismiss as irrelevant because it knows what's relevant for you, not relevant for you. So how do we extremely personalize our agent so that it's, it looks like the best software for you personally, right, given your unique circumstances? And that is a very, very hard thing to do, but you know, we are very excited about some things we are doing there.
Jake Aaron Villarreal: Yeah, that's so cool. Well, I'm excited to see where it goes. You know, there's a lot of listeners that are first-time founders and, you know, you've gone through this a few different times. What's one lesson that you've learned as a leader that you can share that maybe you wish you would have known, or maybe you just learned and you now know it's really valuable that you can share with the world?
Ambuj Kumar: Yeah. So I believe when you're doing your best and not expecting anything in return. The truth is that, you know, your product could be best, but you know, a customer might choose somebody else because, hey, maybe they are using that vendor already. And so you will get, you may get disappointed. Or you try to raise money and you pitch to a VC and you know, they may pass on you because guess what, you know, they don't have money to spend in their fund, right? And or you may try to recruit somebody and you really want them, but you know, maybe their spouse always asks them to work for a large company. So you cannot control the outcomes. But what you can control is that if you love what you are doing and you are giving 100% there and you are being intellectually honest and building a team of good people who support each other and push each other towards greatness, sooner or later you will see that great things will start to happen to you. And this has worked really well for me, and I have seen lots of great companies follow that. So that is something I...
Jake Aaron Villarreal: Yeah, thanks for sharing that. And Ambuj, thanks for sharing your time with us today. It's really good to learn about what you're bringing to market, and I know there's a need for it. So if anybody wants to find you or find Symbian, where do they go?
Ambuj Kumar: Yeah, I mean, Symbian.ai or find me, Ambuj Kumar, on LinkedIn or X.
Jake Aaron Villarreal: Very cool. Well, thanks for joining and thanks to the listeners for listening. It means a lot to me you spent your time with us today. I'm your host Jake Aaron Villarreal signing off for now. We can't wait to catch up with you all in the next episode. Until then, Ambuj, the world. Take care.
If you like what we're doing, don't forget to subscribe, leave a review on Apple Podcast or wherever you listen, and follow us on YouTube where we go behind the scenes to learn what it takes to be a startup founder.