Hacker News new | ask | show | jobs
by cbHXBY1D 98 days ago
FYI, Wiz investor and current Wiz board member Gili Raanan, head of Israeli VC Cyberstarts, has been (credibly) accused of paying bribes to major CISOs for buying software from their portfolio companies like Wiz.

Calcalist did a deep investigation into it: https://www.calcalistech.com/ctechnews/article/b1a1jn00hc

5 comments

This is well known in cybersecurity circles. I mentioned here[1] a couple years back that I know CISOs who've had to clean up big messes because their predecessor was on the Cyberstarts payroll, but on the bright side I also know a couple of those predecessors who were fired for it.

Cyberstarts is the most blatant offender, but to be fair, VC has turned into the next rung on the career ladder for CIOs/CISOs, whose role is otherwise generally terminal (unlike e.g. COO or CMO). So a lot of deals get done now just on giving CISOs a path into VC. It's more subtle than Gili's way, and just as effective.

1. https://news.ycombinator.com/item?id=40487846

About 20 years ago I quite liked the idea of becoming a CISO - the CIO I worked for at the time talked me out of it - saying that the role would largely involve being ignored then, when something inevitably did go wrong, you'd get sacked.
The board of a Fortune 1000 financial services company just fired the CISO and Deputy CISO because they did too good a job cataloging all of the risk in their infrastructure. Now that it's documented and defensibly quantified, the company is somewhat obliged to do something about it, and the board was not thrilled.

It can be a rough gig.

Not a lawyer but this looks like a grey area and since it's public it can be assumed everyone is trying to do it. I worked for F500 and one of the VPs was pushing some IT vendor solution that didn't really fit, after so much implementation pains and half working product release the said VP left the company... To become a board member of that IT vendor.
Too late now!
:)
I for one am shocked that an Israeli VC might behave unethically
How is this even legal? I'd think even basic conflict of interest rules between vendor and purchases would stop this.
It's almost certainly not legal (it could probably be tried as fraud), and it definitely is a breach of contract for the CISO. I'm not claiming it happened, I have no idea, just commenting on the legality of the claimed acts.