Taylor Pierce: Progress, Not PDFs
Starts with a 20 minute pre-interview call. I handle everything else.
About this episode
Taylor Pierce is the co-founder and CEO of Sidekick Security. He spent fifteen years selling application security for other people, went through three acquisitions, and then built the firm himself with about five thousand dollars each in the pot.
Sidekick has no sales team. It runs a partner network instead, and it is built to leave clients with progress rather than a hundred-page report nobody reads. Pierce covers where “progress, not PDFs” came from, the mistakes security leaders make when they hire consultants, and how AI removes the overhead layer most consulting firms carry.
In this conversation
- Where “progress, not PDFs” came from, and what it replaced
- Why a consultancy chose a partner network over hiring sellers
- The mistakes security leaders make when they hire consultants
- How AI removes the overhead layer most consulting firms carry
- Why a pen test should tell you more than which five bugs were found
- Bootstrapping the firm with about five thousand dollars each
Full transcript
Welcome back to another Agentee Digital podcast. Today, I'm pleased to have Taylor Pierce from Sidekick Security. Taylor, it's great to have you here today.
>> Mikulas, thank you for having me. It's my pleasure. I'm looking forward to diving in.
>> So, Taylor, tell me more about kind of your backstory because you spent about what, 15 years on the vendor side of application security. You went through three acquisitions and so kind of what was the moment where you decided you'd rather you know, build your own consultancy than actually keep selling for one. >> Yeah, no, definitely.
That's a that's a great question. And for better for worse, it's it begins many moons ago. So, my dad actually is a serial entrepreneur.
He started you know, two different companies kind of over his career. So, I definitely had that kind of entrepreneurial bug and interest in starting my own company from a very young age. And then my first job out of college, I just ended up at this company called Sigital.
And it was a amazing place to work and was there for about 5 years and worked very closely with my now, you know, co-founder and partner in Sidekick, Robert Wood. We used to travel a bunch and you know, work very closely together and we used to sit around and talk about we'd love to start our own company one day. And that was back in like 2012, 2013.
And you know, I continued down the path of you know, wanting to you know, grow into sales leadership and Robert went down the security practitioner path. He was a CISO for two different technology companies and then Centers for Medicare and Medicaid Services. And you know, we had remained close friends, but the stars kind of aligned you know, last year and we decided, hey, you got to it's a you got to do you want to start a company, right?
It only gets harder every year that passes and you get further down the road in your career and yeah, I think it's something that I would have regretted later in life, never kind of taken that the chance and really trying to do something cool for ourselves. And then also, that you know, we started the company kind of post chat GPT AI, >> You know, era. >> Yeah.
And it opened an opportunity for us to you know, build a security consulting firm, which we both had you know, spent years working and you know, together back at Citadel, but then you know, me leading go-to-market teams at consultancies and Robert buying consulting services you know, in his roles and you know, we could take a business that we knew very well, but then we were very intentional about building it in a in a different kind of way, right? And leveraging AI to you know, internally to drive efficiency and automation in our processes, so we don't have to have kind of that big layer of overhead that a lot of consulting firms have you around project management, scheduling and resource management, sales and all that kind of thought leadership content, all of that you know, we saw an opportunity to do it fundamentally kind of differently. And then certainly externally for our customers, you know, there's incredible things you can do with AI tools to just provide higher value offerings at the same price point or break down some of the barriers that are common in kind of application and offensive security.
When you're limited to kind of just that very tight scope, you know, scope of work and then an SOW, right? It's can be tedious to just engage and work with consulting firms from just that paperwork and scoping standpoint and we've really tried to smooth a lot of that you know, with Sidekick. >>.
Could you tell me more about Sidekick, perhaps for listeners that might not know you guys? >> Definitely. >> What are you guys best at?
>> Yeah, so we are a, you know, cybersecurity advisory and, you know, engineering company. And so, you know, the way that we think about our business is four main pillars. We have AI security, where we will test, you know, tools or products that have AI in them for things like prompt injection.
We also do a lot of work helping people build AI governance programs. You know, a lot of companies are in this mad rush to adopt and use AI, but they struggle with building like the security strategy around it and the guardrails that are needed to do it in a secure way. And we can help people, you know, very quickly get those in place so that they can adopt AI as, you know, as fast as they would like, but they have confidence that, you know, their data, their customers' data, and the expected behaviors of their products or operations are going to be intact.
We also do program transformation, which is kind of second pillar, which is more traditional kind of program benchmarking, maturity assessments, compliance readiness, if you need like your SOC 2 or something. We do we have an offensive security practice, which does a lot of different types of penetration testing, code review, and advanced red team operations. And then last, but certainly not least, we have Vsec, which is kind of our take on staff augmentation or kind of these vCISO type arrangements.
Whereas, instead of like one person, you know, with one kind of skill set, we come in and understand, you know, who are the who are the personnel at a company, what tools they have, existing processes, and maybe gaps, and then what are their aspirations for the next 18 months, you know, whether it be compliance or building capabilities in house or deploying, you know, specific tools. And once we know all of that, we onboard three team members, a security leader kind of persona, a security engineer, and then a privacy and GRC specialist. So, across those three, we have expertise across the gamut, right?
So, we can just, you know, work with them to execute the strategy that they have in place or just be a kind of virtual extension of their team where they can write us in Slack and say, "Hey, we got this vendor due diligence questionnaire." Or "We're thinking about changing how we do authentication in our application. What are the things we need to consider? Would this approach be, you know, secure?" And we just jump in and do the work or answer the question and there's not like kind of the, "Well, it's going to cost this much." Or, you know, "It takes 3 weeks just to get a statement of work." Our team is just there and ready to jump in and it's progress, not PDFs, is kind of our mantra there.
>> How big is Sidekick now? >> Sidekick is I believe 15 people strong today. >> Okay.
>> And we've grown, I think in the beginning of 2025, I think we had four full-time employees. So, we've added a bunch >> Nice. >> Over the past kind of year and a half.
And then we have a great network of contractors that we regularly, you know, work with that kind of have specialties in like applied cryptography or AI or hardware penetration testing and kind of specialized skill sets that we can bring in and they can help our clients. >> Yeah. Actually, before we started this podcast, I what seemed to interest me is that as a COO, you don't have a sales team.
And so, how does your typical week looks like and what are you personally doing that like a VP of sales would be doing at any other security firm? >> Yeah, definitely. That's a great question.
So, when we bootstrapped Sidekick, so we didn't take any funding. I mean we both probably bought grand in a in a bucket to get to get started. And you know, sales and marketing is expensive, right?
And it's it can be very wasteful, right? Like as you well know, like you know, lead generation and you know, field marketing and hiring, you know, good sales people isn't isn't cheap. And cybersecurity is a very trust and kind of relationship-driven industry just given the nature of, you know, the work.
So, you know, from the very beginning we were intentional about trying to be as kind of partner and channel first as we could possibly be and then creating a program that we call a syndicate, which is a network of, you know, of people that may be, you know, security practitioners, they could be VCs, they could be sales people at companies that aren't competitive but are, you know, in the same conversation space and, you know, we pay them a commission whenever they make an introduction for us, right? So, it's let's say you're a sales rep selling a static analysis tool as part of that application security secure SDL conversation, asking what do you do for pen testing is not a you know, very distant topic from, you know, the current one. And if they're looking to make a change or they don't have a pen testing partner, they can just offer to make an introduction to, you know, to Sidekick.
And if they do that and it goes somewhere, they get a check in the mail. And that's been, you know, a huge driver for our growth. And for us, it makes it really easy to manage, you know, from a cost standpoint but a time standpoint, right?
We can do case studies and briefings on new service offerings and just send them to that group of people, which is I think just nice, 27 folks now. We have like a monthly call where we can talk about what's working or answer questions. And so you just you focus on that one kind of community, all your sales enablement efforts and your updates and you know, your wins and your losses.
And you know, then they go out and you know, help us help us grow. >> Yeah, that's very smart. So you're basically like leveraging other networks.
>> Yeah. Exactly, you know, people who are in the conversation, you know, in the industry, they have their own relationships, they have trust with these you know, with people and they can make the right introductions at the right time, right? And you know, you don't have to scroll very long on LinkedIn to see you some post or some blog or some you know, angry statement around how much spam people get, right?
Like the Black Hat Security Conference is this week and in the lead up to that, saw a lot of people saying like I've gotten 30 calls today, right? About grabbing dinner or going to play Topgolf or whatnot and you know, that's just it's it's annoying, right? And it's a it's kind of nature of the beast, you kind of have to do it as a big company, but it's it's definitely not ideal from a the vendor standpoint, the cost that goes into, you know, $300 a lead is not crazy, you know, but then for clients, it's noisy, right?
So if we can if we can, you know, have a first introduction to a company and it's not coming from "Hey, thanks for hopping on. I know I called you nine times, you know." And it's more you know, we'll and you know, it's it's already kind of a personal and kind of trust-based conversation or introduction and that's certainly the best first impression that we want to have. >> Yeah, it's it's very true.
I feel like whenever I go and scroll LinkedIn, everyone is saying, you know, do more automation, more emails, more AI-generated personalization. >> Yeah. >> But I think like people miss the point of personalization.
Like me writing you that you have a nice toothbrush doesn't help both of us or neither you or me get closer or understand your situation more or be more trustworthy. So it's Yeah, talk to me more about the use of AI because you seem to have a lot, you know, some AI use cases. So where do you currently use AI in Sidekick?
>> We use it everywhere that we can and that it, you know, we're confident in the security of it. You know, from a internal standpoint, you know, it's great for we can capture, you know, from for managers, we have an agent that, you know, can take, you know, call reviews and Slack exchanges and you know, a common knowledge base with people's current skills matrix and their ambitions for their next role or growth areas. And it can, you know, it's basically serves as like a coach towards those that kind of North Star where they want to go with their career.
We also use it in not, you know, not very sexy way, but one of the challenges with the consulting is resource management, right? Like who's who's on projects and what who's available 2 weeks from now? And you have to layer in people's skills, you know, not everybody can do everything.
And so, you know, at prior companies, we'd have like we'd spend 2 hours a week with all stakeholders imaginable just talking about the schedule. Yeah, this project's going to go here. I need someone for, you know, August 18th start and it was just a very labor and time-intensive process.
And so, we've we've got a quality agent that just sits on top of our schedule and lives in or the kind of Kanban we have in Asana. And so, you can just go on Slack and say, "When's our next availability for an AI governance project?" And it just spits it out. And so, we don't we don't have to have a resourcing call.
Another one is writing SOWs and proposals, right? We can feed it, you know, call recordings or meeting notes or scoping documents, and it will just generate a statement of work for us. And that was another area that, you know, in the pre-AI world, I'd spend hours, and every salesperson, you know, on the team would spend hours writing SOWs and proposals.
And so, that's been a huge benefit for us, you know, internally. And then, you know, externally in our service offerings, there's a lot that we can do that's additive. For you know, now, a penetration test, for example, typically doesn't cover like the design like an architectural design or threat model of an application.
It also doesn't always include, you know, a mapping to like your detection response capabilities or your compliance, you know, requirements. And we've we've built, you know, AI into our delivery process. So, now when you do a pen test, you also are getting a secure design review and understanding if you have architectural flaws in your system.
Then we do the pen test, and then in the report, we will take the findings and map them to, you know, laugh rules or, you know, configuration changes in your, you know, EDR. And then, the implications of vulnerabilities to your compliance frameworks. And that it just levels up, you know, you get more value from the pen test, you learn more about your environment.
And it makes, you know, something like a pen test, which is usually a very tactical kind of check the box exercise, and it frames it against a much richer and broader backdrop. So, more people in the organization get value from that, you know, beyond just like, we found five bugs. Yeah.
And there's several other examples, you know, in our service offerings where we can we can do that. So. >>.
Yeah, very strong use cases. Like I really like the proposal one because it's always been such a hassle, especially when you're starting out, right? You have very limited resources and you can just fed the transcripts and it just basically does 90% It's 90% there.
>> Right. >> So, yeah, that's great. But yeah, I want to ask you Sidekick runs on like four principles and I would like to know where did progress over PDFs come from?
And if you could talk more about what it is. >> Yeah, no, definitely. I mean, yeah, I think one of the and I definitely felt it as a vendor and Rob did as well and then he saw it as a, you know, someone buying, you know, millions of dollars of consulting and you hear it, you know, consultants kind of get a bad rap, right?
Cuz they come in, they talk about stuff at a high level, and then you get a 50-slide presentation or you get a 100-page PDF and like that's it, right? And a lot of times that leaves clients, you know, wanting, right? And we, you know, we don't want to do that.
We don't want to perpetuate that, you know, that outcome. So, you know, we are very, very focused on, you know, pro- just get in, and done, right? Like make progress.
Let's not, you know, make a PDF or a PowerPoint the capstone of our delivery, right? You know, we want our customers to fear the day that Psychic goes away, right? Like we want to provide that much value to them and benefit and take the tasks that they hate doing off their plate and just, you know, come in and have a real impact.
And yeah, I think that's the way that we've done that is and it took some time to figure out, you know, what did we feel like was kind of forced consultant stuff in kind of the customer life cycle and journey and what the customers actually value, right? So we certainly don't want to be ghosts. We want them to see and know our faces.
We want them to feel like we have great communication and they're in the loop with how things are going in their projects. But we found that most customers would prefer that to be like a short Slack message, not some email with a weekly brief attachment and a request to review it for 10 minutes together, you know, and so making sure that the that kind of white glove very personalized, very communicative experience stays intact, but then strip away all of the kind of forced structure and formality that yeah, I think comes with a lot of times when you engage, you know, consultants. >> You and Rob actually came at opposite sides, right?
He was buyer managing consultancies at CMS and you were the one vendor as you said. So what's kind of like one of the biggest mistakes that you see security leaders make when they go out and actually hire a consultancy. I think there's probably a couple if I if I may.
Yeah, I think sometime organizations come Yeah, they do their research and they're prepared and they kind of come to that first conversation saying like this is what we want. And some sometimes they're spot-on and that makes it really easy. There's other times where I think you could frame it differently and expand the scope or take a different, you know, approach to reviewing a system or Yeah, again, to use a pentesting example, well, it's like, we want our web application tested, but we don't want the back-end APIs and the cloud infrastructure that's hosted in, you know, to be a part of the scope.
And from a risk standpoint, those are critical components of the attack surface of that app, right? So, sure, we can come in and do just the web application, but we're really not going to give you a full picture of like what your risks are in that system. So, I'd say, you know, doing your homework and knowing what you want and having that documentation is fantastic, but also, you know, having some flexibility and being receptive to, you know, what a what the your, you know, potential consulting partner's recommending without just kind of being defensive and thinking it's like an upsell attempt is a is a big one that's ultimately going to lead you can lead to a much better outcome.
Yeah, I think the other one is like hiring too many consultants, right? Like, I think you consulting is a is a people business and the more you can, you know, consolidate and work with a smaller group of vendors of any kind, but certainly consultancies, so that you, you know, the consultants learn your environment and your people and that makes them better at what they do and more efficient and it costs ultimately costs less to the customer. You know, and allowing them getting them the scope to allows them to really be a strategic partner cuz they understand your application program better than, you know, many, many people who work in the organization, right?
Because they have visibility across different teams and of all the tools and all that good stuff. I think that's another big opportunity that a lot of times isn't considered. >>.
I know Sidekick still in the early days, but would you do anything differently if you would be starting today? >> No, I don't think I would. I mean, it's you know, it's it's going We're in certainly in the early innings.
It's going really well. I mean, one of the things that we did when we first started, you know, AI tools weren't where they were today. And so, we used a tool called N8N.
That was kind of one of the early tools allowed you to kind of build a genetic workflows. And we had this crazy N8N project some workflows. And you know, they were great, but they did take time to kind of maintain.
And you know, and it also was difficult to get everyone in the company like into N8N and kind of sharing those workflows. And so, we struggled with that for like probably a year. And then Claude got so good and kind of built in more features that we canceled our subscriptions to like six different point AI tools.
And now we are, you know, kind of exclusively on Claude. And that's been a game-changer for us. You know, we can we have meetings to share you know, you know, cool things that people are building.
And we have a skills library and plugins. And every time Claude has a new release, somebody checks it out. Then we schedule a little like 15-minute huddle, and they can just share with everybody how it works, what it does, opportunities that could be applied to, you know, internally or externally.
And so, that's just really helped keep everybody aligned around one tool, and people getting progressively, you know, better and deeper in their skill set and using it. And it also makes it easier to, you know, protect and make sure that it we're using it securely. >> Yeah.
Yeah. I used an item to kind of before Claude Code, and I feel like nowadays we are more and more moving from UI like basically 90% can be done in the terminal, and I think also like all of the new apps and startups are starting to build more like, you know, MCPs and APIs, and I think UI will disappear in the future. What do you think?
>> I agree. Or it'll change to be much It'll be it'll change to be a different type of UI, but like I you know, I was an English major in college. Like furthest thing from an you know, software engineer, but I use Claude Code, right?
And it really isn't that hard, right? And I can always even in call, you know, in the terminal just say, "Here's what I'm trying to do. How do we How do we get after it?" And it leads me in the right direction, you know, I don't have to have like a note sheet of, you know, how to change directories or all the little, you know, shortcuts that are in terminal that non-technical people typically That's like the first hurdle is like, "What do I do in this thing?" Right?
And Claude Code just removes that barrier. And then when you spend enough time in it, and you go back to like even the Claude, you know, kind of chat, you know, I guess it's like claude.com, it kind of feels like other nets a little bit, you know, because you're you're you're limited in what you can do. >> Yeah.
Yeah. Yeah, I think UI as a whole is very slow. You have to click around when you can just speak to Claude and it can just do the thing.
90% of the time it's it's good. The other 10% it screws up, but it's getting much better. >> Definitely.
>> How does How does Sidekick, you know, in the future look like? What's kind of on the horizon for you guys in terms of growth? >> Yeah.
So, I think you know, what we've been you know, doing more and more of this year and where we want to get to is kind of that you know, new term or you know, service as software, right? So, the conversation with customers is not being figuring out how we're going to do the work and what that approach and methodology is going to look like, but just talking about what's the outcome you're trying to achieve, you know, like what is the final product or the workflow or the outputs and then building, you know, building automated processes and building you little products that just deliver that for a customer, right? So, I give you a common thing in cybersecurity is a is a risk register, right?
A something you use to track all of the different you know, compliance or security risks. And there's massive enterprise tools that are you know, great for that, but many companies, especially kind of mid-market, they don't need all the bells and whistles of a enterprise, you know, leading risk register platform. They just need something that's a little bit better than Excel, which is what they're doing it in today.
So, I we had a client that you know, was going to spend $110,000 I believe on a enterprise, you know, GRC platform as a risk register. We were able to build, you know, a risk register for them in a week and a half that certainly didn't do everything that the enterprise tool does, but it did everything that they needed it to do, right? And now, you know, we delivered that and now our team via the Vsec manages that whole process.
So the customer don't have to buy tools, they don't have to, you know, onboard multiple vendors, they don't have to figure out who on their team is going to be the admin for this new tool. They're just getting a risk register delivered to them that they can access. They don't have to maintain it.
It's always up to date. And, you know, if we go away, they still have the risk register. Their team just manages it, right?
And I think that's where I think that's where the industry is kind of going. And, you know, we definitely want to be a part of that kind of change of yeah, moving to services software. >> Yeah.
Yeah. Okay. Well, Taylor, for people that want to check you out or check Sidekick, where can they do so?
>> Yeah, www.sidekicksecurity.io is the best place probably to start. You can write us at hello@sidekicksecurity.io or you can write me directly at taylor@sidekicksecurity.io. I'm on LinkedIn.
Feel free to reach out there as well. >> Awesome. Thank you, Taylor, for joining.
>> Thank you. Appreciate the opportunity to chat with you.
Grab a slot and we will record.