Cybersecurity doesn't have an innovation problem. It has a noise problem.
New security startups are emerging at a relentless pace, many promising to solve problems that didn't exist a few years ago. AI is accelerating that cycle even further, producing everything from autonomous penetration testing to agentic SOC technology.
For CISOs, that should be good news. More innovation means more ways to defend organizations against attackers who are also moving faster. Except there's a problem: How do you figure out which of those companies actually matter?
John Barrow deals with that question from an unusual position. He's the CISO at JB Poindexter & Co., where he oversees cybersecurity for a parent company of multiple manufacturing businesses. He's also co-founder and managing partner of LaunchPoint Collective, which works to connect emerging cybersecurity companies with CISOs and other security leaders.
He believes the way the industry traditionally introduces startups to security buyers is badly in need of an overhaul.
“There’s a lot of amazing technology coming out that people need to be aware of,” Barrow said during a recent episode of CYBR.HAK.CAST. “But there’s so much noise. Like, how do you cut through that noise?”
Full CYBR.HAK.CAST episode and related article:


Cybersecurity startup speed dating isn't working
Barrow has attended plenty of the startup showcases familiar to many CISOs. A venture capital firm assembles perhaps 10 portfolio companies. Security leaders are invited to an event. Each startup gets a few minutes to explain what it does. Then comes the inevitable question: Interested?
Barrow's reaction is often much simpler: I don't even know what the technology is yet.
Of those 10 companies, perhaps two are relevant to the problems he's trying to solve. The others aren't necessarily bad companies or bad technologies. They're simply a poor match for his organization.
Meanwhile, many of the people attending these events aren't necessarily there because they're actively looking for emerging security technology.
Full coverage of CYBR.SEC.CON 2026:

The result is a model that isn't particularly efficient for either side.
That frustration helped lead Barrow and his LaunchPoint co-founder, David Sledge, to ask a different question.
Instead of putting as many startups as possible in front of as many CISOs as possible, what if somebody did more of the filtering first?
LaunchPoint evaluates startups based on factors including the founders, their backgrounds, the technology they're building and whether the company appears capable of making a meaningful impact. It then looks for early-adopter security leaders whose organizations and problems align with what those companies are trying to solve.
It's essentially an attempt to replace cybersecurity startup speed dating with matchmaking.
CISOs may not be able to wait for technology to mature
Buying from cybersecurity startups has always involved risk. Established vendors have established products, larger customer bases, mature support organizations and long track records. Startups may have none of those things.
Barrow knows that calculation well. But his conclusion is not what you'd expect from someone responsible for protecting a large manufacturing organization.
Roughly half of his security program uses startup technology. That approach has occasionally raised eyebrows among his CISO peers. Barrow said that when he began talking about technologies such as agentic AI SOC capabilities and autonomous AI penetration testing a year or more ago, some security leaders questioned why he'd trust them.
Now, some of those same people are coming back to ask him about the technology. Why the change? Attackers aren't waiting for security technology to mature. AI is increasing the speed and volume of attacks and shrinking the time defenders have to react. Barrow believes that changes the risk calculation around emerging security technology.
“I don't think we have a choice anymore,” he said. “You have to embrace startups to be able to keep up.”
For years, the conservative cybersecurity purchasing strategy has been straightforward: Let somebody else be the early adopter. Let them discover the bugs, integration problems and operational headaches. Buy once the technology is proven.
But what happens when the threat changes faster than the established security stack? Waiting carries risk, too.
AI is making the discovery problem bigger
The AI boom illustrates the problem particularly well. Barrow and the CYBR.HAK.CAST hosts discussed a growing collection of technologies that would have sounded experimental not long ago.
Autonomous AI penetration testing. Agentic SOC analysts. Agentic security engineers. AI identity and access management analysts. AI governance, risk and compliance capabilities. Even purpose-built security LLMs designed to help defensive teams respond at something closer to attacker speed.
Some will become important cybersecurity technologies. Some won't. CISOs don't have unlimited time to figure out which is which.
That's the fundamental problem with cybersecurity's current startup ecosystem. The more rapidly innovation happens, the harder technology discovery becomes. Security leaders don't need another list of 100 hot cybersecurity startups. They need a better way of determining which three might solve a problem they actually have.
Early adoption doesn't mean blindly buying technology
There's an important distinction in Barrow's approach. Embracing startups doesn't mean chasing every new security technology that shows up in a pitch deck. In fact, his own process is deliberately selective.
Barrow initially evaluates technology against problems his organization is trying to solve. If something looks promising, he brings it to his technical experts. They see the technology, evaluate it and discuss whether it belongs in their environment.
They're the people who will actually use it, so Barrow wants them involved before a decision is made. That may be the missing piece in the early-adopter conversation. The choice isn't between buying only mature technology and recklessly throwing startups into production.
There's a third option: Get better at evaluating emerging technology.
Know the problems you're trying to solve. Find technologies aligned with those problems. Vet the people building them. Put the technology in front of the practitioners who understand the environment. Test it. Challenge it. Then decide whether the potential advantage outweighs the risk.
Because the volume of new cybersecurity technology isn't about to slow down.
Neither are the attackers.
The competitive advantage may increasingly belong to security organizations that can separate meaningful innovation from noise faster than everyone else.
Turning CYBR.SEC.CON into a cybersecurity startup discovery engine
That need to separate meaningful innovation from noise is also behind a new partnership between LaunchPoint Collective and CYBR.SEC.Community.
The two organizations are using CYBR.SEC.CON 2026, Sept. 15–16 in Houston, as a vehicle to bring emerging cybersecurity companies together with the CISOs, practitioners and early adopters who are actually looking for new approaches to security problems.
Barrow initially approached CYBR.SEC.Community CEO Michael Farnum with an ambitious idea: Bring 20 to 30 promising cybersecurity startups to the conference and make emerging technology a much more deliberate part of the experience.
As of the CYBR.HAK.CAST recording, LaunchPoint had 21 startups participating in CYBR.SEC.CON in various capacities. Some will have booths. Others will participate in events or presentations. Three of the five finalists in the conference's LaunchPad startup competition came through the LaunchPoint network.
But simply adding another collection of startup booths would recreate the problem Barrow is trying to solve.
The idea is to make CYBR.SEC.CON a place where the filtering and relationship-building can happen differently. LaunchPoint is vetting emerging companies and bringing them into an environment where security leaders and practitioners can spend time with the founders, understand the technology and determine whether it addresses problems they actually have.
That extends beyond the conference floor. LaunchPoint is organizing a pre-conference gathering along with smaller lunches, dinners and other events designed to give founders and security leaders more opportunities for substantive conversations.
The CYBR.SEC.Community-LaunchPoint partnership is an attempt to test another model: fewer random introductions, more deliberate connections. That won't solve cybersecurity's startup discovery problem by itself.
But it's a place to start.


