August 10, 2026

Episode 66: From Chemical Engineering to Cybersecurity with Nuria Manuel

Join Den Jones as he sits down with Nuria Manuel, co-founder and CEO of Veriom

About our guest

Nuria Manuel

Nuria Manuel is co-founder and CEO of Veriom, a London-based cybersecurity company building Architectural Intelligence, catching structural failures before they happen. She started in process and systems engineering specialising in fault detection, later scaled security and QA at a venture-backed software company, and ran her own consultancy digging into vulnerability root causes, before founding Veriom to map organisations’ entire technical architecture and find structural weaknesses before they become vulnerabilities.

Connect on LinkedIn

Watch & Listen on Your Favorite Platforms

Watch on YouTube

Transcript

Intro:

Just before we get into today's episode, we experienced interview fraud. So this is everything from fake profiles applying to proxy interviews where people are swapping themselves out mid-interview or AI fraud. But we hear a lot about it and that's why we launched 909 Shield. It's a platform that keeps you safe during that interview process. Learn more at 909shield.ai. So let's get on with today's episode. Hope you enjoy the show.

Narrator:

Welcome to 909 Exec, the executive leadership podcast from 909 Cyber where cybersecurity intersects with business strategy. Your host is Den Jones, founder and CEO of 909 Cyber. For more than three decades, Den has led enterprise security at Adobe, Cisco, SonicWall, and Banyan Security, helping executives navigate risk, trust, and transformation. Each episode goes beyond headlines and hype with conversations that matter to leaders shaping the world of technology. So please join us for 909 Exec, episode 66 with Den Jones and Nuria Manuel.

Den:

Hey everybody. Welcome to another episode of 909 Exec, your podcast for an executive journey where hopefully we give you some wit, some wisdom, and a few life lessons along the way. Ideally, you're going to share this with your friends, but if you think it's shit, please just don't tell them that. Just don't share it at all. But we assume you're going to love this because we get great guests and today's like no other. Now, Nuria Manuel from VeriOM, you'll be able to explain that in a second. So we met a while ago. We have been setting this up for a long time and someone's a busy lady and this guy's also a little bit busy from time to time or just very flaky. One or the other. But Nuria, welcome to the show. Why don't you introduce yourself so I don't screw it up anymore?

Nuria:

Thanks for having me, Den. I'm Nuria. I'm co-founder and CEO of Veriom. We're a cybersecurity company based in London.

Den:

Now I was digging into your past a little bit, so this has not always been your journey. So let's talk about life in London now. So born and bred London and grew up there and young kid. Were you always into technology? I mean, when you were a young kid, what did you think you were going to be when you grew up?

Nuria:

That's a great question. So I was raised in London. I'm actually, I was born in Angola. So I'm Angolan, also part Portuguese, but born in Angola, moved over to London when I was very much a baby, so around three years old. And - That's

Den:

A big decision for a three-year-old.

Nuria:

Yeah, I know. Made the decision all on my own with no help of my parents whatsoever. But no, so we moved over to London, grew up in North London, so in Angel, Islington. Absolutely love it. My family's still there. And when it comes to technology, I was always a really curious kid. I think one of the biggest things for me was always trying to understand how things worked, and that would mean breaking a lot of stuff. And I would say I kind of inherited that from my dad actually. He was always really, really curious. He'd always bring components home and try to disassemble them or disassemble the TV and show me how things worked. And that sparked my curiosity a lot when I was much younger. And I ended up finding a passion in engineering. I didn't know it was called engineering at the time, and I came across it by the time I was in secondary school.

So in secondary school we had, I think I was around 11, 12 years old. We had a student from, I believe it was Oxford or Cambridge who was studying mechanical engineering at that time. He did a talk about the different types of engineering that you can get into. And as soon as he said, "Hey, it's all about the process of understanding how things worked," that sparked my interest. And I was like, "This is exactly what I like. This is exactly what I've been doing." So from the age of around 12, I knew I wanted to be an engineer. I knew I wanted to get involved in understanding how things works, breaking things. And I set on that path in secondary school to just focus on everything engineering related that got me into university. I actually didn't come through a security, so I know I run Varium, which is a cybersecurity platform, but I didn't come through security the conventional way.

My background is actually in chemical engineering. That was the path that I decided to take because I loved everything with materials. I loved everything to do with processes. And so I chose chemical engineering and I spent my early career in the manufacturing sector at a company called Cummins working on fault detection systems. I ended up specializing in predicting the likelihood of failures occurring in the production line as well as with diesel engines and found, as cheesy as it sounds, a massive passion, everything AI, machine learning, robotics related, and decided to do a career shift and go from the manufacturing sector to the software industry working for a venture-backed software development company.

Den:

Wow. There's a couple of nuggets in here. So first of all, for those who are very familiar with football or soccer in the US, North London ha s two great teams. One's called Arsenal and one's called Tottenham Hotspur. Which one do you guys support?

Nuria:

Arsenal. Always. Okay.

Den:

You can stay on the podcast. If you said sports, I was just going to cancel it right there. I'm like, screw that. Yeah, it's for me. Yeah, a lot of my friends here don't really get the whole football thing. Well, they still call it soccer.

Narrator:

The

Den:

World Cup I think helped them a lot because that just happened recently. But I can't wait for the Premier League to start again. And let's see, Arsenal ideally surpassed their accomplishment of last year where they won the Premier League and they got into the final of the Champions League.

Nuria:

Let's go.

Den:

So yeah, a bunch of people that I know that watch this, they're football fans and stuff. But yeah, North London, two famous football teams. If you've never been to a football match, I would recommend go check out either of those because they're better than Chelsea. Yes. Anyway, now the other thing though, when you were in school, I'm pretty impressed where your high school, first year high school, they call it grades here. My two kids are old now, but I still never got into the first grade, second grade. And you're like sophomore or I don't care. All I really know is first grade, so we were about 11, 12, we're going into year one at high school. Yes. And it seemed so very early on that I guess maybe inspired by seeing your dad and him doing that stuff. You're like, "I love this shit. I want to figure stuff out." And engineering is the thing.

Nuria:

Yes.

Den:

So when you were thinking of engineering, I mean, were you wise enough to think of a specific type of engineering? Because the chemical part is certainly a lot different than software engineering or robotics or whatever, right?

Nuria:

Exactly. Not at all. Not at all. I had no clue. I had a high level understanding of different types of engineering. So mechanical engineering, chemical engineering, electrical engineering, mechatronics engineering. And I'd spent a lot of time, and I have to thank my secondary school for this, my high school for this, but we had a really good career service. And back then, anything to do with a career was in a huge textbook. So it was a textbook where they'd go through everything and they'd go, "If you like maths, if you like science, these are the opportunities for you." And it was very manual, so nothing automated. But they would sit down with us and go through the options that we had. And I didn't know which engineering I wanted to go towards. I just knew I loved anything with most of the things that I did at home in understanding components and how they work, like a calculator, for example, or even a Barbie doll.

We had an automated barbie doll and I'd break it apart to understand the mechanism and how it worked. It was all towards electronic and mechanical engineering, but I also liked chemistry. And I would have to say this is very much due to my mother. So my mom would buy me endless science kits when I was younger. And I may have broken a bunch of things in the house because of it, but I'm innocent until proven guilty with some of the stuff that we're breaking around the house. But she would buy me endless science kits. I'm saying science experiments. I had my first microscope when I was younger as well. Oh, sweet. It was like a TV and I did wild experiments like taking a sample of my dad's beer and putting it under the microscope and going, "This is why you shouldn't-"

Den:

Oh no, you can't go waste the beer like that.

Nuria:

Geez.

Den:

Waste

Nuria:

The beer and everything. So because of that, I had a passion for both chemistry and engineering. And chemical engineering, I would say, really became an area of interest when I turned around 16, because I started spending a lot of time understanding the concepts of different types of engineering groups like aerospace engineering as well, because I was also obsessed with space.This is how you know it was so broad. I loved space. I loved chemistry. I loved anything to do with components. And so I had an abundance of choice, but I made the decision to go down the route of chemical engineering because it touched a lot of the areas that I was interested in. It touched mechanical engineering, electrical engineering, and aerospace as well. So I was like, "I'm getting the best of both worlds by going into chemical engineering." There's literally a textbook on thermodynamics that explains the history of chemical engineering, and it basically says mechanical engineers didn't understand each other.

Chemists didn't understand each other. So they came together and they formed chemical engineers and chemical engineers work across a variety of different fields. And what I got from it the most was systems and process engineering and the importance of that across a variety of different fields.

Den:

Oh, wow. That's pretty cool. I mean, already you've surpassed my knowledge of engineering disciplines. I'm like, "Really? All of that. Okay. It also seems very rare. In IT or cyber, it's very rare that there's females kicking around. So when you were doing this, I mean, were you the only female in class or was there more of you? Because I can't imagine 10 years ago or whatever in high school, you've got a big swell, a groundswell of females. I mean, even here, it's strange even now to get a decent percentage. So were you the only one or was it a group of you?

Nuria:

Yeah. It's funny you say this because I was actually warned when I was in secondary school and high school about going into engineering. And it was my teachers, my male teachers that encouraged me to go into it more. And the main reason why I was warned was because not many women were going into the engineering field, but I had a passion for it. And I was like, "This is what I want to do." And I had amazing, amazing teachers that really supported me with that decision. And they were like, "Go and do it. You're good at this. You have an understanding of it. Go and do it." There were about, I would say chemical engineering is probably one of the engineering disciplines that has the most women in it, but we're still talking around, if you're saying a class of 30 students, there'll be about four to five women in the group.

And that's the most that you tend to see.

Den:

And that's actually quite a high percentage really, right? Yes. Exactly. 25% or 20% still feel like, "Oh, wow, success."

Nuria:

Yeah. It's like, "Oh yeah, no, we made it. We're here." So you don't necessarily feel, at least with everyone in my cohort and everyone in my class, we didn't talk about it as much because we knew the reality. We knew what it was like. But you're all there, you're all doing the exact same thing. You're all working towards a common goal, which is becoming a chemical engineer, becoming a chartered engineer, and getting a really, really good job, and obviously finishing university with really good grades. So you're all there to really support one another. So as much as you can see it, it wasn't something that massively impacted a lot of us, at least the ones in my cohort. Yeah.

Den:

Yeah. It's a surprising career choice for a female so young to really have that shit. When I was 11 and 12, I mean, I just think I just wanted to do music and be a pop star. And I don't think that worked out actually so well. I'm still on that path, I guess. So when we come back, so we'll take a brief break, but when we come back, I want to really dig into the origin story of now becoming a founder. So everyone will be back shortly. Hey folks, just want to take a minute to say thanks for listening to the show, watching the show, however you engage with us. If you're liking the conversations, if you think we're adding some value, we'd love you to like, subscribe, and share the show with your friends if you know of anyone else that would benefit. Ideally for us, that will help us be able to grow the show, invest more in the quality, get some more exciting guests, and keep bringing you some executive goodness.

Thanks everybody. Take it easy and enjoy the rest of the discussion. So Nuria, let's talk about this. So you go from being a chemical engineer. Yes. And I think you were saying you were doing a lot of assurance type work and quality type work. How did you get from that to then suddenly thinking, "Hey, I'm going to start my own business?"

Nuria:

That's a really, really good question. So when I was a chemical engineer, when I was studying chemical engineering, I spent a lot of time getting a lot of experience. So I worked in oil and gas, wastewater treatment, construction, the commission of an energy from waste facility. I spent a lot of time working, getting experience, understanding exactly how things worked. And I ended up landing a role in the manufacturing sector, so working for a company called Cummins, specialized in product validation, so understanding failures in the field and using root cause analysis, Six Sigmas. I very much specialized in lean Greenbelt Six Sigma. And then started specializing in fault detection systems. So looking at failures, predicting failures, using a lot of machine learning concepts. And one of the things that I learned in the manufacturing sector is it's a world where you're not looking for a single just broken part.

You're looking at how an entire system of interdependent processes behave. And you're trying to catch the point where a small deviation somewhere is going to cascade into a failure downstream before it actually happens. And I became quite obsessed with that process that I'd spent a lot of time learning whilst in the manufacturing sector. Coupled with the fact that I was working on fault detection systems. I loved anything to do with AI and machine learning and robotics. To give a bit more context, at this time, I had left London. I was working up north, northeast England in an area called Darlington. So it was Darlington where there's a lot of different manufacturing sites. So I believe one of Amazon's largest warehouses is there as well, but there's a lot of different industries and manufacturing was a core part of it. And I would come to London as much as I could, but especially around London Tech Week.

Because I spent so much time on fault detection systems, I started studying and looking at software myself, so independently. It wasn't something that was a core of my role, but it's something that I started getting really interested in. I loved how to build algorithms that allowed you to predict failures, how certain components or a change in one system could impact another. So you change a hardware component, it has a huge impact on the software itself and you have to update the software. So became quite obsessed with that. And so I'd come to London Tech Week every year and started seeing what was going on in the tech industry. And I was like, "This is what I am looking for. I've got that process and systems engineering background and experience from chemical engineering. I've developed this experience in fault detection systems, in root cause analysis from the manufacturing sector, and I'm seeing where the industry is going and the industry is going into automation, technology, software, AI." And this was before the AI as we know it today.

So I'm still very much on the linear regression side of things. And so I made the decision that it was time for a bit of a career change and I decided to move over to the software industry. So work for a vendor.

Den:

How old were you when you made that decision?

Nuria:

If you don't mind me asking. Oh, no, no, not at all. So this was in 2018. So I would've been in my mid - 20s. So I was in my mid - 20s around that time. So your

Den:

First big decision, three years old, I'm getting out of here in London. Mid - 20s, you're changing the career. So was there a time before that area where you had maybe a mentor in your life that was giving you some sage wisdom along the way? Because you were doing some pretty, I'm going to say pretty intense kind of roles up until that point. You're in your early 20s. So is there one piece of wisdom that stuck with you in your early 20s that you can share? Oh,

Nuria:

Yeah. I had great managers, great managers that supported me and gave me a lot of confidence. I like to give an example. So rather than a piece of wisdom, there's two specific examples actually. I'll make it short. So first one, my first week at Cummins, it was very intense. So the second day that I joined the company, they said, "We have a project for you and you are going to lead this project." And the project was on turbochargers. I studied chemical engineering. I had no idea about turbochargers and how turbochargers worked themselves. I was still in the process of understanding, "Hey, I'm now working for a diesel engine manufacturing company that develops power component systems. I'm trying to understand how these systems actually work." And they went, "Here's a project for you to manage and for you to lead and for you to be able to get to a solution.

So we're having these issues. We need you to identify the problem and come up with a solution with a team that you are going to manage. Imagine being fresh out of university and that's one of the biggest things that they give you." And I was like, "Okay, I've been put into this." In the first couple of days of me managing the project, I remember getting to a point where one of the senior team members had mentioned, and I'm happy to share this, he'd mentioned that I probably was inexperienced and I wasn't the right person to probably lead the project, and it could have been someone else that would've been in a better position to lead the project. And I understood. I was also -

Den:

Probably him. Yeah, exactly.

Nuria:

Probably

Den:

Him

Nuria:

Comment. I was disheartened, but I understood. I was like, "I'm fresh out of university. I'm just in this process. I do have some work experience, but obviously this is a huge deal. It's a big project and we knew what the financial impact was." And I remember my manager who was the head of reliability engineering at the time had a conversation with me and he said, "Absolutely not. We put you in this project for a reason and you are going to lead this project and you will find a way to

Come up with the solution that's necessary." And he's like, "You have all the tools here. You can ask all the questions that you need." So then I started thinking because of his courage, because of his belief in me, I started thinking, okay, what's my background? My background is in process engineering. It's in systems engineering. I've worked in wastewater treatment, oil and gas. What's the common pattern that I noticed? Well, in all of my areas of expertise or my work experience, I've always managed projects that were all about improving systems or understanding why something is broken and implementing a solution. That's something that has happened throughout my internships and the work experience that I gained. So I started focusing on the problem itself. As I write, we have this problem. It's impacting X number of vehicles. Let's go back and trace why this happened in the first place.

What are the design issues that have been implemented? What are the things that have occurred, the changes that happened, the software updates that were made that would've led to this? I spent probably most of my day, in one of the days, most of my day gathering data and insights from everyone everywhere, calling people who designed the first systems that were implemented in the vehicle that I was working on, and got to a point that I had a presentation, presented that to the entire team, and ended up finding what the issue was, as well as a solution that hadn't been implemented before that week trial. And I remember still feeling not super confident because inexperienced, I've been told by the team that I'm also inexperienced. And I remember saying to them, "I've just gathered this insight. So if all I can do is help in gathering more data, I'm happy to do that.

But here's the information and I found that there's actually a solution that we haven't tested. So the best thing we can do is test the solution and see if it works." Because of that, the same person that mentioned that I was inexperienced, we ended up running the tests and then we did a big presentation across the entire team. And he stood up and he apologized. I didn't expect an apology. I wasn't expecting an apology, but he apologized, stood up and basically said, "This was incredible, and we've done a fantastic job in delivering the project on time." So we delivered the project much faster than we ever anticipated. So that was one example. The other example is I had an amazing mentor called Susan, and she was fantastic. I did a lot of work in the product validation side, and it was to the point that she was like, "You are ready for a promotion.

You're ready to become a senior fault detection systems engineer." At this point, I'd spent so much time on hardware and some software components that I didn't feel like I was ready myself. And there's a lesson here of imposter syndrome and not feeling confident enough. But I remember her going through all of the things that I'd done at the company. I was one of the youngest people to work on a $300 million project that we had. It was one of the biggest projects that we had at that time, and I'd led that. And she showed me that as an example. And she was like, "You're absolutely ready and I'm not going to say no for an answer. So we're going to offer you this promotion and you're going to accept it. I'm not taking it no as an answer because even if you are not confident, you don't feel like you are ready, you learn when you are in the position that you get to.

There's building blocks. You are never going to be fully ready." And I had to learn that rather than being super obsessed and focused on being a perfectionist in that sense.

Den:

Yeah. And I mean, both of those are great examples. I mean,

I hope people take some good nuggets here because the first example, I look at it like you're the male boss that could quite easily have caved and went, "Yeah, you're right because he thinks that you're not confident and that's why you're bringing that statement to him." But he'd done the opposite. He built your confidence up. And one thing that I've learned, especially women tend to not apply for things or ask for things the same way guys will do. That imposter syndrome thing I think is even higher in females than males. And I just think it's incredible to be in a position to say, "No, I trust you." And I think one of the things is you obviously have the background, but the other thing as well is as the new person in that role, that second day of your job, you actually come in with a lot of curiosity

That

Some of the people who have been in the job longer, they'll discount things just because they'll think, "Oh, we've done that before, or that was obvious." But you wouldn't. You'd be questioning all the time. And I've picked up that from you from our conversations and even today. Yes. The second one I think is brilliant because you shouldn't promote somebody to a job when they've checked all the boxes.

Narrator:

I think

Den:

It's very important for people to realize you promote someone into a job where they're still headroom to grow into the job and surround them or support them in a way that enables that. So many times I see companies not promoting people because they're not quite there yet. And it's like, well, if you do the job, you get there quicker. Is that your sense from those experiences? Oh,

Nuria:

Absolutely. It's the belief in the people around me that also gave me the confidence to go beyond what I believed that I could do. So I had a tremendous fear of failure. That was something that I was very much a perfectionist. And that came from all the way from secondary school to primary school to being like, I have to have good grades basically. So I had a deep fear of failure. And I always wanted to make sure that to me, comfortable or being comfortable meant having everything perfect, but perfection doesn't exist. It doesn't exist.

Den:

But isn't it bizarre how someone who analyzes system failure for a living has a fear of failure? Yes,

Nuria:

Exactly.

Den:

I'm like, holy shit, that's strange, right?

Nuria:

Exactly.

Den:

Yeah. So let's dig in because this is the one thing. So why don't you share with everybody what is Verium? Yes.

Narrator:

And

Den:

How did you get from the, "I'm going to London, I'm hanging out tech week," to the, "Okay, now I'm going to build something." So let's talk about that step.

Nuria:

Absolutely. So it wasn't a straightforward line whatsoever. So from Cummins, I moved to a venture-backed startup leading governance. So when I joined them, they didn't necessarily have governance in place. So they built software for enterprise, mid-market, as well as early stage companies. And by governance, I'm referring to QA and security. So I joined them initially as a technical project lead. And after a month, they pulled me into an incredible project and they wanted me to QA the project and also do some initial penetration testing just to verify if there were any issues and if they met all of the customer's requirements. And very quickly saw that there was a strong need for Governance that was required in the company. So after a month, transitioned from a technical project lead over to managing QA and infrastructure security for the company. And that's where I bui lt and basically scaled a team from scratch and ended up leading an extended service offering on top of that.

Den:

I mean, at that point you hadn't been in the security game, right? Yes. So what was that transition like? I mean, you do penetration testings. It's like, hey, what.

Nuria:

It was very interesting because engineering concepts and principles tend to come from very similar methodologies. And if you notice, a lot of the methodologies actually align with manufacturing principles, and the same is true for cybersecurity in this case. And I remember the CEO of the company at that time, I had a conversation with him. His background was in aerospace engineering and he'd mentioned to me, engineering is basically the same with different terminologies. You're using different words that apply to very similar concepts. So I'd done penetration testing at Cummins with some of the work that we had to do because we had to do it for fault section systems. But the penetration testing for a software, like a core cloud-based software component is very different to penetration testing on a diesel engine. So I spent a lot of time learning what it actually meant to run a penetration test on a software component.

So actually looking at your code cloud, CICD, production, all of that, but saw the similarities and the principles that I had learned starting all the way from chemical engineering over to the manufacturing sector and basically applying that knowledge into QA and infrastructure security. And I feel like that gave me quite a bit of an advantage because I was obsessed with creating process maps. So one of the things that you would always see from me is a boardroom or a whiteboard filled with maps lining up how everything is interconnected with one another. And I would literally draw it out because that's what I was used to from a process engineering perspective. So to me, software was no different. I would map everything and use that map to assess key areas that I need to test, analyze, add more coverage to. And then also on the penetration testing side too.

Den:

Yeah. Yeah. And it's cool that you're bringing in the whole mapping piece because when we met several months ago, we're having lunch and you're sharing with me what Verium does. And the mapping thing and your website's called the what and the why and all this business. Jump into how did then this translate into a, I can turn this thing into a business?

Nuria:

Yes. So very, very quickly, I spent so much time in QA and security. And obviously when you're working for a software development company, you are feeling the impact directly of any issue. And by impact, I mean the financial impact of what it means to have a bug, to have a vulnerability, to have something that's been exploited. You're feeling it directly as a company and you are very in the weeds of building the systems directly. So I'd worked on multiple different projects and I got to a point where became obsessed with shift left. Shift left from a security perspective, shift left in understanding how to build better products. And the shift left that existed to me still wasn't enough because we were still in this endless cycle of patching vulnerabilities, patching something that had already been broken. So using my background in the manufacturing sector, I decided to actually leave the company that I was working for. I started my own service auditing infrastructure for critical vulnerabilities, but focused on tracing it to the root cause. Why are these happening in the first place? What are the patterns that we're seeing, the design flaws, the structural weaknesses that are being implemented early that would lead to vulnerabilities?

And I did that three and a half years servicing highly regulated sectors, so healthcare, FinTech, and got to a point where I was like, there is something here. There is something here that we can absolutely automate, not just on the service perspective, but we can completely automate the process of seeing design flaws, patterns, et cetera, that are being implemented much, much earlier in the software development lifecycle that would inevitably lead to vulnerabilities or an area that someone can exploit. So in one sentence, what Verium does is that every tool finds what's wrong. Verium shows you the structural why. And more importantly, we find the weak points before they turn into incidents. So concretely, we map a customer's entire architecture. So from their code, their cloud, their CICD and production, we pull that into one unified graph. We do that in under an hour and it's completely automated.

And that map surfaces structural weaknesses. So the places where the systems are designed and connected where it creates risk. So not just a single, for example, misconfigured resource. It works whether you're a team shipping something brand new or a team that has a massive legacy system. What we're doing is mapping how everything is interconnected, all of your trust boundaries, all of your services, all of your data. And from that surfacing where the structural weaknesses, the weak points, design floors are much, much earlier in your development process.

Den:

And you mentioned highly regulated environments. Does that tend to be the customer that knocks on your door the most?

Nuria:

Yes, 100%. The reason being is highly regulated sectors, there's a strong need from a security perspective to have the right processes, governance in place because of the compliance. So if we look at it from a compliance perspective, they're adhering to certain frameworks such as ISO 2701. SOC two, if you are a health tech business as HIPAA, HIPAA has specific encryption requirements, how PII data is stored, et cetera. And a breach within a highly regulated sector costs way more than for businesses that aren't necessarily highly regulated. If you're looking at GDPR data policies, on average, it's around 10 million for a severely critical breach within a highly regulated organization. So they feel the impact more because of the amount of confidential information that they're dealing with, but also all of the compliance requirements that they have to adhere to.

Den:

Yeah. So if I was going to explain this to my kid. Well, actually, if I was going to explain this to my kid 10 years ago, because he's older and wiser now, he'd probably get this ship pretty quick. But if I was going to explain it to a five-year-old, is it a case of you're going to find weaknesses in their architecture or their system that are exploitable from a bad actor perspective as opposed to weaknesses from a BCP or DR?

Nuria:

Yes.

Den:

Or is it all of the above?

Nuria:

Exactly. It's from a exploitable bad actor perspective. So anything that can easily be exploited within your code, cloud, CNC and production. And one of the simplest way that we say is we help companies build stronger, more secure software, but specific to their architecture.

Den:

And this is why when we met, I was like, oh shit, this is pretty cool actually. Because I get the sense that if a customer leverages your platform, one thing's going to happen is that they should expect they will have less vulnerabilities at the end of it. Yes. Or less vulnerabilities they're unaware of really.Because they might choose to accept the risk, but at least they're aware of it. Obviously they're reducing the risk of a breach or something of that nature. What does a typical engagement look like?

Nuria:

That's a great question. And to answer your question on the vulnerabilities, absolutely, because we're purely focused on the structural weaknesses. So before they're even a CBE, before they're even a vulnerability, and a significant proportion of breaches are actually due to structural weaknesses and design flaws, security and control failures that are implemented much earlier. They're much harder to identify with traditional scanners. Traditional scanners are specifically focused on a point in time defect, which in this particular case is a vulnerability, is a known CVE that it can track and then fix in this case. The engagement is pretty straightforward with customers. One of the biggest things with our platform, because it's automated, the most important thing for us was ensuring that we have the right level of integrations set up already. So we have a library of integrations. It's read-only access. We're not making any modifications to an organization system.

Takes under an hour for you to get set up onto the platform, and you get what we call automatically an audit. So an audit is a report which breaks down the issues that we've identified, but also more importantly, you get an architectural map. So that's a diagram of how every part of your system is interconnected with one another. As you know then, and you've probably noticed, I'm obsessed with processes and maps, so we absolutely had to have.

Den:

You're going to get a diagram and a post-it note and a map.

Nuria:

And

Den:

What's really funny as well is you're also blending in terms that are infrastructure engineering terms as well, right? Yes. Do you find your customers can use the output as input into a better CMDB or input into an actual audit? Because you used the word audit, but I would suspect that some of this is actually very good evidence that reduce costs during an audit or really good information that can help your CMDB because we all know CMDBs suck. They're pretty almost always wrong. So unless you spend a boatload of money to automate updating them even then they're still not usually right.

Nuria:

And it's a lot of work. So yes to both of them. Actually, we integrate with tools like Banta, Drata and Sprinto, and the information can be passed to auditors because the information and data that we collect is something that a CTO or CISO would have to do manually. Let's say you're in a middle market organization, you are going through ISO 27001 or SOC two. We're not a compliance platform, but because we map your systems and how everything's interconnected with one another, and because we're doing a scan to detect structural weaknesses, compliance is a big part of that, especially if you're a highly regulated sector. So there's no security about that compliance piece as well for organizations. So we embed those frameworks. We're running checks against ISO 27001, but from a technical perspective, so that information can be passed back to the development team, the engineering team on, "Hey, we've captured this particular issue and it doesn't align with this particular framework within ISO 27001." That information can be supplied to tools like Bantadratis, printer or auditors because that's the information that a CTO or CISO would have to collect manually themselves.

And I've spent countless times with heads of engineering, heads of security, CSOs and CTOs who are just bashing their heads in having to spend so much time collecting this evidence, these artifacts manually. And so we have that as part of the platform itself.

Den:

And to be fair, I think a lot of CISOs like to bash their heads to begin with. I mean, it's sometimes a thing like that. So either bash their heads or we meet at the bar, we'll actually redo the latter. The other thing I was thinking is from a cost savings perspective, saves on audits and stuff, do insurance companies like this? Because I mean, I get the sense that from a risk for insurance companies, this might help them negotiate better premiums, right?

Nuria:

Yes. I love that you asked me that because we're in the process of partnering with two insurance companies for this

Den:

Exact reason. By the way, Mario, we had this conversation. It's all about the money. I tell people, no CEO woke up in the morning and though, I'd love to spend more money on security. They just don't want to be in the news and

Nuria:

Things

Den:

That help you. If your technology has an ROI that's really, really quick, then people love it because it's like, "But it'll save me time here, here, and here, this is a great win," right?

Nuria:

Yes, exactly. So one of the biggest areas from a cost savings perspective of our platform is on the insurance side, because we collect insight on where are the exportable parts within your software. So we essentially have a full artifact of your entire CodeCloud, CICD production, your entire software system. When it comes to insurance, insurance companies, when they're looking at your premium, they're looking at information that's widely available. Information related to your software, your application as a technology company is not information that's widely available. So they don't have access to that insight, but we do. So we can provide that insight and that information directly to insurance companies to lower insurance premiums. So we have two partnerships that we're in the process of forming because of this exact reason. But it's incredible to hear from insurance companies themselves that this is something that they've been wanting, but the access is limited. Being able to trust and provide that information to an insurance company is slightly different versus a technology company as ourselves, a cybersecurity technology company, having those artifacts available that you can share to insurance companies directly.

Den:

Yeah. And that makes absolute sense. And I used to talk to insurance companies about like, "Oh, if you've done a zero trust implementation, what does that do to the premium? Blah, blah, blah, blah, blah." Now you guys are a UK-based organization. You're a little rinky-dinky startup. When we met, you were out here as part of a government initiative, and you're raising funds, and you're basically pounding the streets, and I think you're doing that again now. So what's it like life as a founder in the UK? What's it like trying to raise money there, work with the government there and all those initiatives? And then what's your experience as you're trying to do that and break into the US market?

Nuria:

That's a great question. So life as a UK founder, there's a lot of opportunities in the UK. There's a lot of government support, there's a lot of accelerator programs, so there's a lot of initiatives. However, it is relatively slow from a fundraising perspective. And let me dive into that in a bit more detail. Basically, the opportunities are there, the support is there. However, resource is limited. And by that I mean it's not that we don't have funds in place to support UK startups. It is available. But the UK is naturally an extremely risk-averse nation country.

So proof points are super, super important to be able to move much faster. But when you're an early stage company, you do not have those proof points readily available. And it takes time to build those proof points. A great example is we raised a pre-seed and we raised a pre-seed around late 2024. And when we raised our pre-seed, we were still asked about traction. It was super important for the investors, pre-seed investors, that we had proof of traction, proof of customers that were coming in and revenue. And when you're an early stage company and you're just in the process of building a product and you are kicking off your go-to-market strategy, you don't necessarily have all of that in place.

Lucky for us to an extent, because I started off running a service company, we actually had a lot of our customers on the service side willing to use our product and be design partners for our product. So we had evidence from that perspective. And obviously given my background with everything related to processes, I'm very much data obsessed as well. So I was like, I will go in with those proof points and I will show letters of intent and I'll show all of the information that's required. But it's a slow process and it's been a slow process for a lot of founders. And I would say not necessarily just on the preseed stage, but on the seed stage. So just last year, spoken to a bunch of founders who were in the process of raising, and it was taking them a year and a half to be able to raise a good seed round.

A lot of it has to do with the tractions that we're seeing in the market with the market's going towards with the rise of AI agents, AI platform systems, but then also the concern of risk, especially in the UK market. So that's one of the biggest challenges that we found. However, the government support is there. We managed to land an excellent opportunity with a program through an organization called Plexel. The program was Cyber Runway. They sponsored us to represent the best of British cybersecurity for RSA, for the cybersecurity conference here in San Francisco. We spent a week here. We had an amazing time. And what we got out of there was a lot of traction, a lot of investor conversations. And it was to the point that myself and my co-founder decided to stay out of pocket.

Den:

We had that conversation. You also had probably the best ramen you had had that week as well.

Nuria:

Yes.

Den:

I remembered that really well. Yeah. And you guys done that bold move where you're like, the initiative that had funded you're coming here ended. Yes. And you guys were like, "We're having such good conversations. We're going to stay a bit longer." Yes. And then you stayed longer. And then you've came back again. So you're back out pounding the streets. Before we hit record, you were telling me you're getting about four hours sleep a night. I don't know if that's jet lag or just pure enthusiasm to walk the streets of San Francisco. So yeah, what's the experience like on your second time around

Nuria:

Here? Yes. Yes. I will dive into the experience of my second time by just quickly highlighting the first time. So our presence, we had very little presence here in the US before we came to the US. We have one US customer and that was it. So our presence was negligible here. But given RSA, one of the things that we did, and I highly recommend this for everyone, we were selected to present to CISOs, government officials, and investors as part of RSA. So I have 16 companies, five were selected to do that, and we were one of the five. One of the things that we wanted to do, because our platform specializes in architectural weaknesses, slightly different to traditional application security tools, vulnerability management platforms. We didn't want to be another company showing a brochure of, "Hey, this is exactly what we want to do or this is exactly what we do." Instead, we wanted to be a differentiator. And one of the ways to get people to understand exactly how the platform works is for them to be able to run it themselves. However, you're in a conference, people are either on laptops or they're walking around on their mobile phones, and they're mainly on their mobile phones.

So what we ended up doing two days before RSA is build a mobile-ready version of our platform to allow people to scan a QR code and set up their integrations directly on their phone and run an audit. So we had that set up. We had 47 people scan it. We had people asking us where we were going to be in the following week. We were meant to be back in London, we're meant to be back in the UK. And we had people invite us for meetings, investors as well as prospects wanting to meet, wanting us to have a conversation in more detail about our platform because of the traction that we were seeing. And given our experience in the UK, we were like, "We can't leave this opportunity on the table." So myself and my co-founder made the decision to stay out of pocket. We decided to take the risk ourselves and pay for the trip and the extra stay out of pocket and did the stereotypical scrappy founder staying in seven different places for the purpose of having those interactions, having those engagements, including staying at Tenderloin, which was fun.

Den:

Yeah, we had that conversation. I remember that. I'm like, "Holy shit." I'm like, "You guys are keen, right?" But that's the other thing as well is that week, I mean, hotel prices in San Francisco that week are just ludicrous. So I always tell people I grab Airbnbs. So RSA, I'll always jump onto Airbnb and usually end up in a suite in the Donatello for my whole stay is usually less than the price of one night room and the bloody Marriott marquee or whatever where they jack the prices up.

Nuria:

Yes.

Den:

Yeah,

Nuria:

Exactly.

Den:

And you're back again for more punishment and pain. Actually, so at the end of that, the lesson learned, I mean, I think there's one thing, which is sometimes you're just going to have to think on your feet and say, "I know that that was the plan, but we're going to take the opportunity and think on our feet and just stay." And that gamble, I think we had the conversation since then. I think that gamble paid off. I think you got

Nuria:

More

Den:

Customers.

Nuria:

Yes, we did. We onboarded a customer in 48 hours. In under 48 hours, I like to use that metric specifically. It was a customer that we met at a hotel lobby and health tech business took us through everything cybersecurity related. We demoed the platform the next day early in the morning, and they automatically asked us how much does it cost? Sign me up today. So we onboarded a customer in under 24 hours. The next customer we onboarded in under 48 hours. And then we also got investment whilst we were here. We managed to connect with some amazing investors

Narrator:

Who

Nuria:

Received in the business who are cybersecurity operators and who jumped in and invested in the company. And yes, we've come back for more. One of the biggest things, one of the lessons I would say that I got from this experience was being comfortable stepping out of your comfort zone. I'm very much someone who loves a good plan, a good process, a good strategy. There was no planned process or strategy in place for this, but there was a big opportunity. And we knew if we wanted to take the business to the next level, it wasn't going to be staying still and waiting for opportunities to happen. It was going to be chasing after those opportunities ourselves and seeing the traction that we were getting, the conversations that we were having, and actually going after it and moving forward with it. I'm very much an introverted person, and so it takes a lot for me to go, okay, let me go ahead and push for this.

But we did it and we had to do it and we had to step out of our comfort zone and really push forward. And sometimes that's what it takes for you to get to the next level is being able to do something that you would naturally be uncomfortable doing. And we have to.

Den:

Then you're back for more. You're back for more. You're like, let me do that again.

Nuria:

Yes. We missed it. We went back to London. We were like, wow, no, this is crazy. We have to go back to San Francisco. And one of the biggest things that we wanted to do, we noticed absolutely our product market fit was here. The traction that we got was incredible. The traction that we got here would've taken us the same size of companies, people who were speaking to key stakeholders, it would've taken us around seven months to be able to get the same traction in the UK.

Den:

And then you guys are setting up a company, a US-based company. I'm assuming there's going to be a Delaware registration? Yeah. Exactly. People say California or Delaware, but if you want VC funding, Delaware's the cleanest option from what I hear. Absolutely. And are you guys going to go to BlackCat while you're here? Because that's a couple of weeks That's the plan. Yeah.

Nuria:

Yes, that's

Den:

The plan. I'll be there. Well, we'll be there. We've got our team there. We are way over. This is insane because I didn't realize the clock just taken up there near you. So I'm like, oh fuck. Oh God, we're way over. So yeah, I would love to have you back on the show because I think one thing as well, so you guys are raising money or are you done raising money or you're back to raising money?

Nuria:

So we're in the process of closing out our raise. When we were here a couple of months ago, we opened up a really good safe. We had some amazing investors come in and we're closing out the safe whilst we're here. So we're here until the end of August, and we are also closing out customer conversation. We've had some amazing customer traction. We had some customers that are larger organizations, so I mentioned the two insurance companies. So we're getting them onboarded onto the platform whilst we're

Den:

Here. Beautiful. That is awesome. Congratulations. Thank you. Yeah, when we met, I was like, holy shit. I've bounced around this industry for so long and very rarely do I see something that I'm like, "Oh, this is different." Because everyone tells me their shit's different, except the 500 AI companies that have spun up in the last probably 12 months. A lot of their shit's the same. Or it's the same old crap and they used AI twice and they now call it an AI company. Oh, 100%. Yeah. So I'd love to have you back on. We should definitely catch up more. Yes. There's a lot more. Yeah. Next time I'd love to dig into the where are you now? But then what's all these lessons that you've learned? Because you guys are moving at such a pace that it's insanely cool to watch.

Nuria:

Thank you.

Den:

Thank you very much, Nuria. This has been awesome. Everybody, Nuria Manuel from Veriom, thank you for coming on the show.

Nuria:

Thank you so much then. I'm really happy to be a part of the show and I'd love to come back.

Den:

Yeah, awesome. Well, I mean, it was hard enough to get us together the first time, right? So holy shit. We'll start planning the next one now. Yes. Now. Thank you very much. Hopefully everybody enjoyed this conversation. There's a lot more to come and thank you, Nuria. We'll speak soon.

Nuria:

Perfect. Speak soon. Thank you.

Narrator:

That wraps up this episode of 909 Exec. If you found value here, subscribe and leave a rating to help others discover the show. To learn more about 909 Cyber, our advisory services, and how we help organizations secure growth, visit 909cyber.com. Thanks for listening. And until next time, lead with clarity, build trust, and stay secure.

← Back to all episodes