Episode Summary
Executive Summary: The conversation explains why enterprise security is less about flashy nation-state defense and more about scalable hygiene: knowing assets, patching systems, and detecting anomalies across huge, dynamic environments. Orion Hindawi argues Tanium succeeded by replacing hub-and-spoke architecture with a peer-based model that can inventory, query, and secure endpoints in seconds, while also saving money through operations use cases.
Main Topics: Why legacy endpoint tools fail at enterprise scale (Priority: 5/5): Hindawi says traditional hub-and-spoke systems were built for tens of thousands of machines, not hundreds of thousands across cloud, VMs, branches, and remote work. Their architecture cannot coordinate endpoints quickly enough or flex with modern infrastructure. Tanium’s ground-up architecture redesign (Priority: 5/5): Tanium spent years rebuilding communications and security from scratch because client-to-client interaction breaks the assumptions of conventional encryption and coordination models. The product’s novelty is structural, not cosmetic. Security as endpoint hygiene, not cinematic defense (Priority: 5/5): The core security thesis is that most breaches are enabled by poor visibility, missing patches, and unknown devices—not just elite attacks. Tanium helps customers discover where attacks landed and how far they spread. Operations ROI funds security adoption (Priority: 4/5): Tanium spans security and IT operations, letting customers justify the platform through software/license savings and then apply that budget to security. This combination makes large deals easier to approve. Platform vs. point solutions (Priority: 4/5): Hindawi argues that many point-solution vendors solve overlapping problems on top of the same data and mainly exist because they can create service-heavy businesses. Tanium’s platform can add modules faster and avoid multiple agents and consoles. Perimeter security is necessary but insufficient (Priority: 5/5): Firewalls and network defenses reduce noise and block some attacks, but they cannot provide complete protection because the perimeter is porous, work-from-home is widespread, and many paths into networks exist. Mobile and IoT are the next frontier (Priority: 3/5): Hindawi is skeptical of current MDM solutions, especially Apple’s enterprise posture, and sees the more promising long-term approach as embedding Tanium-like communications deeper into chips and connected devices.
Key Arguments: Legacy endpoint management is too slow because it assumes 5,000-10,000 machines, not 500,000+ distributed devices. Tanium had to rebuild core topology and security because client-to-client communication invalidates standard hub-and-spoke assumptions. Breach response improves when companies can ask every endpoint what it is experiencing and locate anomalies immediately. Security and operations should be sold together: operations provides measurable ROI; security provides urgency. Most point solutions are overlapping views of the same underlying data, so a platform is more efficient than many separate tools. Firewalls and perimeter defenses only reduce noise; they do not guarantee prevention or visibility into what got through. The best security posture is to know your environment, reduce attack dwell time, and limit blast radius rather than promise impossible prevention. Many customers are now receptive because they know existing tools are failing and they want an answer to that failure. Tanium’s deployment model and lack of services incentives force the product to be lightweight, scalable, and fast to implement. Mobile device management remains broken because enterprise needs conflict with consumer OS vendor philosophies, especially Apple’s.
Data Points: Large banking customer endpoint count: 500,000 computers - Used to illustrate why old hub-and-spoke management architectures no longer scale. Deployment architecture rewrite time: 5 years - Time Tanium spent rebuilding its platform from the ground up. Engineering team size during rebuild: 12 engineers - Small team built the new architecture over several years. Breaches in last year bought by Tanium: 8 of top 10 breaches - Hindawi says most major breach victims later became customers. Remaining top breaches in procurement: 2 of top 10 breaches - The other two were still in procurement at the time of the conversation. Telco network entry points discovered: 1,500 ways out - A customer initially believed it had 22 ways in, but Tanium tracing found many more paths. Perceived network entry points: 22 ways in - What the telco thought it had secured with expensive perimeter controls. Security spend per network entry point: $7 million a year each - Telco example of heavy investment in perimeter protection. Customer endpoint detection speed advantage: Seconds vs. days - Tanium can identify issues in seconds while legacy systems may take days. Typical endpoint growth at customers: 10% to 15% per year - Hindawi says endpoint counts are still increasing across customer environments. Estimated current market size: $20 billion - Tanium’s stated total addressable market for its current scope. Potential additional module opportunities: 40 more things - Hindawi says the platform could extend into many more productized use cases. Forensics module build team: 4 engineers - Example of how quickly new modules can be built once the platform exists. Forensics module build time: 6 months - Demonstrates leverage from the existing platform architecture. Credit card processor pilot deployment: 100,000 computers in 3 days - Example of rapid adoption and deployment in a large enterprise. Common 100,000-seat deployment time: Less than a week - Typical rollout speed cited by Hindawi. Largest deployments: Few weeks - Deployments of 450,000 to 500,000 endpoints. Antivirus/other security CPU burden: 50% of computers’ time - Illustrative example of security tooling becoming too intrusive when stacked together. Legacy antivirus CPU use: 10% + 5% + 3% + 2% - Cumulative overhead example used to explain user frustration. Idle SQL Server copies found: Hundreds - A pilot uncovered many unused installations, creating major cost savings. Unused SQL Server spend: Hundreds of thousands of dollars per year - Estimated savings from removing redundant licenses.
Pivotal Quotes: "It is the thing that will fix you." — Orion Hindawi: On endpoint hygiene and patching being the real answer to most enterprise security problems. "We had to take a completely refactored approach to the problem." — Orion Hindawi: Explaining why Tanium spent years redesigning endpoint management beyond hub-and-spoke architecture. "The perimeter is not a protective mechanism. What it is useful for is reducing noise." — Orion Hindawi: Describing the limits of firewalls and network defenses in modern enterprise security.
Implications: Enterprises should prioritize visibility, hygiene, and rapid remediation over perimeter-only defense. The winners will be platforms that unify security and operations, reduce tool sprawl, and scale across cloud, remote work, and future IoT/mobile environments.
About The a16z Podcast
The a16z Podcast discusses tech and culture trends, news, and the future – especially as ‘software eats the world’. It features industry experts, business leaders, and other interesting thinkers and voices from around the world. This podcast is produced by Andreessen Horowitz (aka “a16z”), a Silicon Valley-based venture capital firm. Multiple episodes are released every week; visit a16z.com for more details and to sign up for our newsletters and other content as well!