Please introduce your company and give a brief about your role within the organization.
WeSecureApp, a 5-year-old Dallas-Hyderabad-based cybersecurity company solving important challenges in the application, network, and cloud security space. With a mixed bag of experienced & certified professionals along with maverick bug bounty folks, we were able to deliver innovative cyber security services to 150+ global customers.
As the CEO of this company, I am responsible to lead the company’s short-term & long terms goals. To achieve that, I would wear multiple hats and that includes strategy, sales & marketing, client relations.
What is the story behind starting this company?
I founded WeSecureApp five years ago with my cousins, Akhil and Srini. With that deep family history, we knew each other’s strengths and working style in such detail that it was a no-brainer to band together to offer consulting services to enterprise customers.
Unlike some cyber founders, I am not deeply technical. With an MBA and a keen eye for business building, my strength is in strategy. In fact, this helped identify the potential for WeSecureApp, when he witnessed Akhil earning significant money in applying his hacker skills to bug bounty programs. Akhil earned amazing respect in the hackers community not just in India but worldwide. Even Akhil had an entrepreneurial mindset and was very excited about the idea of a Cybersecurity start-up.
Srini with his two decades of experience in the US joined us with his incredible product management skills and; I took business strategy and Akhil the technical.
What are your company’s business model–in house team or third party vendors/ outsourcing?
As a cybersecurity company, we have built an amazing team of security professionals, engineers, and developers to cater to our client's requirements. All our services are delivered through an in-house team and the product is also built by our own engineers and developers.
How does your company differentiate itself from the competition?
Our team and methodology to perform security assessments help us to be ahead of our competitors. We have designed a hybrid methodology which is a combination of in-house tools, open-source tools, and manual testing methods that helps us in finding critical and business logic vulnerabilities.
What industries do you generally cater to? Are your customers repetitive? If yes, what ratio of clients has been repetitive to you?
As of today, we have over 150 global customers and a majority of them are from the tech industry that includes Fintech, HealthTech, Internet, Travel & Tourism apart from Banking & financial customers. More than 85% of our customers sign up for an annual subscription and 90% of them are repetitive.
Please share some of the services that you offer for which clients approach you the most for?
Application Security – Penetration Testing and Secure Code Review.
Infra Security – VAPT and Red Team Assessment.
Cloud Security.
What is your customer satisfaction rate according to you? What steps do you take to cater to your customer’s needs and requirements?
Even before signing the contract, we thoroughly understand the objectives behind the security assessments and consulting, and accordingly prepare an SOW. Upon signing off, we do have a kickoff call with the client and re-confirm the scope, share the project roadmap, milestones. We are very transparent in our communication and always available to them. Nine out of 10 customers give us a 5-star rating (Excellent) for our performance. We take our customer’s feedback very seriously and work towards achieving the highest standards to provide an amazing experience.
What kind of support system do you offer to your clients for catering to their queries and issues?
There would be a dedicated SPOC assigned to every client and an escalation matrix is mentioned in the SoW and Kick-off presentation. Our clients even communicate with security professionals to get support for fixing the issues. For all PO issues, we respond within 2 hours.
What kind of payment structure do you follow to bill your clients? Is it Pay per Feature, Fixed Cost, Pay per Milestone (could be in phases, months, versions etc.)
The payment structure is based on the engagement model and subscription package. Our current engagement model includes -
- Ad Hoc / One-time assessment (Fixed Bid)
- Time & Material
- Annual Subscription
Do you take in projects which meet your basic budget requirement? If yes, what is the minimum requirement? If no, on what minimum budget you have worked for?
As per our engagement model, we take ad-hoc/one-time assessments and the minimum budget for the same would be $5000. Of course, we also do pay POCs to prove our capabilities to get a larger engagement.
What is the price range (min and max) of the projects that you catered to in 2020?
Leaving aside paid POCs, the minimum price that we worked on the ad-hoc project was $8500 and the maximum $125K.
Where do you see your company in the next 10 years?
In the next 10 years, we would like to be known as a top application & cloud security consulting company in the USA with the goal of being acquired by a large enterprise company.