Overview
Yotam Segev is co-founder and CEO at Cyera, a cloud data security company [1]. Prior to founding Cyera, Segev built and ran the cloud security division of the Israeli Defense Force Unit 8200 [1].
Career history
- Co-Founder & CEO at CyeraMar 2021 to PresentCyera
- Head of Cyber DepartmentAug 2018 to Jul 2020Israeli Military Intelligence - Unit 8200
- Talpiot Senior Class CommanderAug 2017 to Aug 2018Talpiot Program
- Talpiot Class CommanderAug 2016 to Aug 2017Talpiot Program
- Cyber Team LeadMay 2015 to Aug 2016Israeli Military Intelligence - Unit 8200
- Cyber Course InstructorJan 2015 to May 2015Israeli Military Intelligence - Unit 8200
- CyberJul 2013 to Jan 2015Israeli Military Intelligence - Unit 8200
- Talpiot CadetJul 2010 to Aug 2013Talpiot Program
Education
Bachelor of Science - BS, Computer Science and Physics2010 - 2013The Hebrew University of Jerusalem
- Educational Leadership in the Military at Mandel Leadership Institute2017 - 2018
- Nativ Program Fellow, Political Science and Government at IDEA - Israeli Center For Liberal Democracy2019 - 2020
Insights & ideas
The through-line
Segev's central claim is that a founder's own convictions are close to worthless as a guide to what to build. "We believe nothing," he says. "We have one compass. Our compass is the customers" [1][6]. He puts his own views in the same bucket as everyone else's: "I have opinions. My co-founders got opinions. My mom's got opinions, too. Like, you know, we don't build products according to those opinions" [1][6]. This is not modesty for its own sake. He traces it to a specific gap: he and his co-founder knew cyber deeply from a decade in the Israeli military, "but we knew absolutely nothing about enterprise cyber security" [1][6], and that ignorance forced a posture of asking rather than asserting. The stance survives scale. Four years in, with the company approaching $100 million ARR [1][6] and later at 1,200 employees and a $9 billion valuation [3], he still describes the whole period as "an accelerated learning journey," adding that "we always joke that we know nothing but we know how to learn quickly" [1][6].
What has shifted is the stage on which that method operates. The early questions were about finding any pain worth solving in a single cloud; the current ones are about what AI does to data risk across every enterprise at once. Segev frames AI as an amplifier rather than a new category of problem: "our business had legs before AI, but with AI, it's got wings" [4].
On the customer as the only compass
The discipline started at the seed round. Cyberstarts, he recalls, told the founders: "Look, your idea sounds like a B minus. And that's a compliment. We're investing in the team. And if the customers tell us they want to buy that, we'll build it. But if they tell us they want to buy something else, we're going to build something else" [1][6]. Luckily, he says, "we didn't build that idea because the customers did not want to buy it" [1][6]. They stayed in the space, pivoted, and found where the real pain sat. The method is relentless interrogation: "leaning into the customers, listening to the customers, asking and asking and asking and asking and every time thinking about what the next question to ask to go deeper on the pain" [1][6]. The questions he cares about are why existing solutions are unsatisfactory, why the problem matters to the organisation, and why, if it goes unsolved, the customer is "utterly screwed" [1][6]. He worked this through with Cyberstarts under what they called the sunrise process, which he credits with forcing precision on the problem statement, because "one degree to the left, one degree to the right over time it accumulates and you end up much further from what the customers wanted" [4].
He is careful not to universalise the approach. Asked where the instinct came from, he replies: "First of all, I don't know if it's the right approach. I think it was the right approach for us" [1][6]. The customer knows what is broken and why, even if they cannot describe the solution, and their guidance runs from top-level strategy "all the way down to the minutiae and details of you know what the UI looks like and what the workflow should be like" [4]. Getting that access takes work: "you go on a first date with a CISO, he's not telling you about all the shortcomings in his program" [1][6]. Trust has to be earned before the useful information appears, and "once you do that, you know, a magical world unlocks" [1][6]. The same compass now governs acquisitions and expansion into adjacent spaces [1][6], and he describes the ability to combine that listening with engineering "at a super super high velocity" as the secret to winning large enterprises as a first-time founder [2].
On validation being dollars, not compliments
Segev refuses to treat enthusiasm as evidence. "Customers might tell you you're the prettiest thing they've ever seen in their lives, but if they ain't willing to pay for it, it means they don't actually value it" [1][6]. He goes further than asking whether someone would pay: the test is collecting, seeing a signature "even though my product is early stage, even though my company at the time was 15 people" [1][6]. Because this is enterprise software rather than PLG, the checks needed "six, seven figures in them" [1][6], and net new ARR is the oxygen: "a company only exists. The oxygen for a company is business" [1][6].
The most counterintuitive lesson is about narrowness. In hindsight, version one was relevant to roughly one customer in fifty, because coverage was essentially AWS only [1][6]. He argues that was a feature: "if the product was relevant for 10 out of 50 customers but mediocrely relevant they might have not taken a chance on us" [1][6]. The customers with a large enterprise AWS estate, including businesses that had just completed a lift and shift, cared intensely and paid up, and that gave the signal [1][6]. He uses the story to steady his sales team today: "back in the day I had to disqualify 49 out of 50 customers because they just didn't have the right tech" [1][6]. The bet was always that the platform would broaden, and it has outrun his own forecasts. Three years ago, he says, what he imagined delivering was "not even 20% of what we actually can deliver" [1][6].
On founder-led sales and how enterprise deals are actually won
Segev and his co-founder generated pipeline themselves and still do, both of them "completely dedicated to the sales motion" [1][6]. In the beginning the hardest problem was awareness for "a seedstage company in Tel Aviv" [1][6], and after that, closing. His answer to both was physical presence: "You need to be on a plane. You need to get to wherever the people are to go meet them in person because nobody wants to jump on a Zoom with you" [1][6]. He notes that anyone can take a Zoom with a million people, so a call proves nothing about who you are [1][6]. The compounding asset in cyber is the density of the practitioner network: "if somebody likes you, somebody believes in you, they have at least three friends that will definitely have a coffee with you too" [1][6].
He learned the mechanics from founders further along, including selling in a pair, "the trusted advisor and the business outcome oriented question asker," with himself as the sales guy and his CTO as the sales engineer [1][6]. He is emphatic that discovery must be prepared rather than generic: research the company and persona, tailor the hypothesis to their business and their plans, so that "instead of, you know, shooting in the dark, you're trying to hit very specific pain points" [1][6]. This is why he sees great salespeople running the same loop founders do. "We're not selling CDs off the shelf" [1][6]; the job is to understand the customer's business problems through curiosity and then "attach the product to real meaningful business outcomes," which is what raises both the value proposition and the deal size [1][6]. He also insists sellers think about buyer timing: a CISO cannot walk into the CFO's office asking for millions without an answer to "why today? Why not yesterday?" [4]. The winning position is to lean into new problems appearing in the customer's world while quietly picking up the old use cases that were never properly solved, rather than pitching a next-generation version of something that disappointed people [4].
On choosing hard technical problems
The team's honest self-assessment was that their strength was technology: "We weren't product experts. We weren't go to market experts at all, but we knew that we can build technology and we can build technology well" [4]. That led to a deliberate filter. Whenever an easier idea came up, his co-founder's response was, "No, Tom, that's not for us. Other teams can do easy things. We're a team that should do hard things" [4]. The sweet spot was defined as problems that matter enormously to customers but are technically brutal [4].
Data security qualified, because the existing market proved demand while failing to deliver. "The existence of tools does not mean that there's a solution" [4], he says, illustrating it with a cracked kayak he bought tools to repair and could not fix [4]. Customers described years of effort, millions of dollars and tens of people on projects that never scaled or produced the intended outcomes [4]. His reaction was optimism: "if the problem is so important that the customers were willing to buy and invest time and energy in tools that didn't solve the problem, what would happen if you actually gave them something that does solve the problem" [4]. Two technical bets followed. The first was deployment. Network-based scanning connects to one data store at a time, which collapses for enterprises with hundreds of thousands or millions of stores, straining network footprint and performance [4]; by latching onto the cloud migration wave, Cyera built a fully agentless approach over API connectivity to the cloud provider, lighting up native and non-native, structured and unstructured stores from a single integration [4]. The second was classification. The Microsoft-era model of employees manually tagging documents as confidential, restricted or public was unreliable self-attestation, and "every part of the data security program that was built on top of that" inherited the noise [4]. Scanning tools replaced it with engines customers had to tinker with, building and maintaining regex patterns, work requiring an engineer you would be lucky to retain six months [4]. Cyera's answer was an AI-native engine that learns a customer's unique data types automatically [4], which he links directly to the outcome security teams actually ask for: "they want to discover the unknown unknowns" [4].
On the 1% of data that matters, and the 12-month blind spot
Segev's differentiation argument rests on triage. Cyber is unusual, he says, because "in most of what we do in our lives, we get measured on how well we do on average. In cyber security, we get measured on our weakest link. Doesn't matter if you're an eight on average. If you still have a two or a three, it's bad" [2]. Against a target where threat vectors, IT and regulation all keep moving, exposures are permanent, so the leverage is in knowing which data is worth defending: the 1% whose breach "would create a bad year for them, not just a bad weekend," separated from the 99% that clutters [2].
The harder version of the problem is that the crown jewels keep changing. He describes a technology company whose core excitement about the platform is being told about new data types that have become prevalent internally, because an innovative company generates new IP constantly and the security team otherwise learns about it by asking the business, leaving them "12 months behind the business" [4]. Those months are the ones that matter: "nobody has a decades of edge on the competitors today. It's 12 months, it's six months that separates you from the competitors from the commodity" [4]. Adaptability is also what makes the platform portable across industries. Every business, and often every business unit inside a large company, holds data sets never seen elsewhere [3], which is why he can point to leading customers across financial services, pharma, telco, media and manufacturing [3]. His framing is human: "we all have secrets as human beings and as companies... It doesn't matter if it's an individual or a 100,000 person corporation, they all share the problem, just the data itself looks different" [3].
On holistic data security and the end of long implementations
Segev argues that enterprise data security has "never actually been done" as a coherent programme: some in the proxy, some in the endpoint, some in email, but rarely an organisation able to identify crown jewels across the estate, keep that current with the business, and protect the data at rest, in use and in motion [4]. That triad is his definition of a holistic data security platform, extended to cover data as it is put into LLMs and queried back out [4]. He believes Cyera is filling that need "probably faster than the customers can actually consume and operationalize this technology" [4]. The underlying premise is that locking data in a vault is finished: in the world of cloud and AI, data has to live and be processed in new systems because that is how value is made, so the job is "to build the right brakes for the car in order to be able to go fast" [3].
He treats deployment speed as a competitive requirement rather than a feature. Traditional enterprise software had long time to value and enormous implementation effort, "and you know, that might have been okay 20-30 years ago, but today we live in a very impatient world" [3]. Customers will not be taken on a multi-year journey at the end of which "they might find the pot of gold"; they want results "every morning, every day, every hour" [3], and he credits the agentless architecture for making that possible and for earning a young company that level of trust [3].
On AI as accelerant, not novelty
Segev's consistent position is that AI has not invented new security problems, it has made the existing ones vastly worse. "It's not that the problems are new. A lot of the problems are the same problems we had before. They're just much much much worse. They're moving at a completely different speed and the risk is potentially 100 times greater" [4]. The same holds on the attacker side: the techniques are broadly the ones we know, "but those techniques are just much more effective, much more proficient, much faster to iterate" [5]. The demand driver is simple economics of the technology, which "feeds on GPUs and it feeds on data" [5], making proprietary data an enterprise's next competitive advantage [3].
He is blunt about the current state of controls. What worries him most is "the pressure being put on the security risk and compliance teams to get out of the way and let AI be rolled out," combined with security capabilities bundled by AI providers that are "very very insufficient," creating exposure whose consequences will show up in the coming years [2]. On LLMs specifically, his working assumption is unsentimental: "you should assume that every piece of information an AI LLM has access to can be made accessible to anybody who can chat or query that LLM," because supposed policies have been shown repeatedly to be foolable [3]. He notes Anthropic's leadership on safe AI and more reliable systems while insisting that for the present, and as far as 2026, data can get out into the wrong hands [3]. Customers voice the circularity themselves: "how are we supposed to adopt AI and do it in a controlled manner when we don't even know what data we have and what data we're feeding into it?" [4]. Agentic AI he treats as the next wave, not yet truly in market but already on every organisation's mind [4].
On why security has to stop playing catch-up
Asked how to balance innovation against security, Segev rejects the premise. "There is no balancing. Innovation is always going to win... security is not going to get the ability to say no" [5]. His preferred image for the change in pace is athletic: "we've been chasing a runner, a regular runner, and now we're chasing a Olympic sprinter," and if security keeps waiting for exposures to happen before closing them, "I think we're going to be left in the dust" [5]. The demand for proactive, preventative measures follows from that speed differential rather than from principle.
The upside of accepting this is that security becomes an enabler. He positions the company as "a way to say yes to AI," opening the guardrails so enterprises can bring AI in with the right monitoring, accountability and preventative controls, "to make sure that AI is the best thing that happened to the organization and not the worst" [4]. He sees the tension clearly in his customers, traditional, highly profitable businesses that do not want to be "the dinosaurs that they went extinct," but equally do not want to be "the risk-takers that were foolish and you know shot themselves in the foot" [3], and who feel their fundamental business model is under attack [3]. His prescription is unglamorous: "Every experienced CISO will tell you it's all about the basics," which here means inventorying sensitive data, knowing what you have, locking it down, and preventing leaks across the many open communication channels [5]. He also warns that the category carries scar tissue. People are burned by past investments that never paid off, and changing that paradigm is hard [5]; his counter is that technology which failed ten or twenty years ago can work now, and that the mindset that broke the Turing test should be brought to revisiting "old and painful problems with new solutions" [5].
On the market and the mission
Segev thinks the industry is nowhere near its ceiling. When the company started, the largest cybersecurity company by market cap was around $25 billion; four years later it was $120 billion, "a 5x growth in 4 years" [5], with the biggest players at 120 to 140 billion against roughly 30 to 40 five years earlier [3]. Rather than reading that as a peak, he calls it "only the early innings of cybersecurity" [3] and expects that four years on the conversation may be about 200 or 250 billion dollar companies [5]. His reasoning is structural: the more digitised and AI-dependent the world becomes, the more cybersecurity matters "not just to protect and secure, but to enable and unlock the value of these technologies" [3].
He attaches a moral frame to that growth. Cybersecurity, in his view, has an obligation beyond day-to-day threat defence: "to make sure that digital trust stays strong in society, that we can trust our institutions, that we can rely on AI" [5]. He is explicit that a good outcome is not guaranteed. "The world is changing fast. And if we think that it's all going to be great, it doesn't have to be. Things can break. Things can break in a way that's irreparable" [5], which is why he describes the work as "one of the most important missions that anybody can dedicate their life and energy to" [5], aimed at the future his children and grandchildren inherit [5].
On partnership and the culture that scales it
The company began as a friendship rather than a business plan. Segev and his co-founder go back sixteen years, from standing in the same line to enlist at eighteen [2], through Talpiot and three years in the same house, then a decade in 8200 [1][6]. The trigger was almost accidental: his co-founder's Pacific Crest Trail plans collapsed when COVID closed the trail, and he called and said quit, let's start [4]. Segev's instinct was to spend time in the civilian industry first; the answer was to skip that and "learn while we do. Maybe it won't be the best company we'll build, but let's get going" [4]. He describes the motivation as building "something meaningful, something important, something we'd be proud of and enjoy leading" [1][6], and he treats the venture as terminal: "This is our first and last" [2].
That founding attitude shows up in who succeeds inside the company. "The people that succeed and do well in our company are people that have a relatively strong introspective capability. They see themselves, they don't think that because they've accomplished things in life or because they've succeeded, they have it all figured out" [4]. He tells every new hire on the onboarding call that "we take the business very seriously but not ourselves" [4]. The same growth mindset is what he credits for the speed of the last four years: showing up "to learn from every person every encounter" and deliberately surrounding yourself with people who can teach you [1][6].
Takeaways
- Treat your own product convictions as no better than anyone else's: "We believe nothing... Our compass is the customers" [1][6], and be prepared to abandon the founding idea if buyers reject it [1][6].
- Validation is money collected, not enthusiasm expressed; a signed six or seven figure check from a 15-person company's early product is the only real proof of pain [1][6].
- Being intensely relevant to one customer in fifty beats being mediocrely relevant to ten in fifty, because only intense relevance makes a buyer take a chance on an unknown company [1][6].
- Pick problems that are important to customers and technically hard: "Other teams can do easy things. We're a team that should do hard things" [4].
- In cyber you are graded on your weakest link, not your average, so the work is separating the 1% of data whose breach causes "a bad year" from the 99% that clutters [2].
- Assume any information an LLM can reach can be extracted by anyone who can query it, because policy controls have repeatedly been fooled [3].
- Security cannot veto AI adoption: "There is no balancing. Innovation is always going to win" [5], so the only viable posture is proactive and preventative rather than waiting for exposures [5].
- Long implementations are disqualifying; enterprises now expect value in minutes and results "every morning, every day, every hour," which is what agentless deployment buys you [3].
Media & appearances
- Yotam Segev, founder and CEO of Cyera, discusses building a data security platform that addresses traditional perimeter-based security limitations. He explains how the company identifies unknown data risks that customers should be concerned about, and how AI has accelerated existing data security problems while making risks potentially 100 times greater. Segev also shares insights on company culture, customer-driven product development, and how Cyera achieved rapid growth to over $6 billion valuation in less than four years.YouTubeCreating a Holistic Data Security Platform: Cyera's Yotam ...
- CyeraYouTubeYotam Segev talks Cyera's journey with Hunters & UnicornsYotam Segev, CEO and co-founder of Cyera (referred to as Sierra in the episode), discusses the company's four-year journey from founding through achieving nearly $100 million ARR and $1.3 billion in VC funding. He shares his early military background in Israeli cyber security with co-founder Tamar, their initial lack of go-to-market experience, and how the company adopted a customer-first approach rather than relying on founders' opinions for product decisions.
- Yotam Segev, CEO and founder of Cyera, discusses how AI adoption is increasing the value and risk around organizational data, driving demand for data security. He explains Cyera's approach of automatically mapping, classifying and protecting data across different customer environments, and notes the company has grown to 1,200 employees with a $9 billion valuation after raising $1.7 billion. He also shares his view that cybersecurity is still in its early growth stages given increasing digitization and AI dependence.YouTubeVideos
- HUNTERS AND UNICORNSYouTubeHow Yotam Segev Built a $6B Cybersecurity Unicorn 🦄Yotam Segev, CEO and co-founder of the cloud data security company (called Sierra in the transcript), discusses his early journey building the company with co-founders including Tamar, his CTO, after spending over a decade together in Israeli military cyber security. He explains how the founding team transitioned from deep tech military work to learning product management and go-to-market strategy, emphasizing that their compass is listening to customers rather than relying on their own opinions, and describes the company's rapid growth to nearly 100 million ARR in four years.
- New York Stock ExchangeYouTubeEpisode 518: Cyera CEO Yotam Segev on Securing Enterprise Data in the Expanding AI EraCyera is accelerating its mission to secure enterprise data in the age of AI. CEO Yotam Segev joins Inside the ICE House to discuss the company’s $400 millio...
- CyeraYouTubeCyera CEO Yotam Segev on TBPN: Listening to Customers and Securing Enterprise AIYotam Segev, co-founder and CEO of Cyera, discusses the company's focus on data and AI security, ensuring data going into AI systems remains private and secure for enterprise adoption. He explains the company's founding based on a 16-year partnership with his co-founder, their background in cybersecurity at the Israeli Defense Force, and their strategy of listening to customers combined with high-velocity engineering to serve large enterprises. Segev addresses concerns about insufficient security capabilities bundled with AI from providers and Cyera's differentiation through identifying the most critical data that would cause significant business impact if breached.
- New York Stock ExchangeYouTubeYotam Segev, CEO at Cyera Joins NYSE TV LiveYotam Segev discusses the cybersecurity industry's 5x market growth over 4 years and explains Cyera's focus on data security as enterprises adopt AI. He addresses AI-fueled threats, emphasizing that attackers are using traditional techniques more effectively and faster, requiring organizations to prioritize data inventory, protection, and preventing sensitive data leaks across communication channels. Segev stresses that security must be proactive rather than reactive to keep pace with AI innovation, and describes cybersecurity as having a moral obligation to maintain digital trust in society.
- Cyera is accelerating its mission to secure enterprise data in the age of AI. CEO Yotam Segev joins Inside the ICE House to discuss the company’s $400 million Series F funding round and how Cyera plans to invest in building a unified platform that conApple PodcastsEpisode 518: Cyera CEO Yotam S… — Inside the ICE House ...
- Amazon MusicWorking in a new space: Yotam Segev, co-founder and CEO of ...
In the news
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.