Founder’s Security Roadmap
CIC Cambridge
From Zero to “Secure Enough”: A Founder’s Security Roadmap

Join Ebryx CEO Ahrar Naqvi security leaders Eric Galis, Nicole Hart, and Elijah Cedeno for a practical fireside chat on building a security posture that fits your company today and holds up when larger clients start asking harder questions.  Please register here to attend live on in person and to register for the larger community.

CIC CAMBRIDGE SESSION FOR FOUNDERS AND GROWING TEAMS
Thursday, August 6, 2026
6:00 PM–7:00 PM EDT
CIC Cambridge 1 Broadway, 5th Floor, Havana Room Cambridge, MA

Security Becomes Urgent Before most Founders Expect it

A promising enterprise deal reaches procurement. A security questionnaire hits your inbox. Suddenly, the decisions you postponed become blockers. Meanwhile, spending on every tool and certification can drain a young company without solving the right problems. This session will help you find the middle ground: a defensible baseline that matches your stage, protects what matters, and gives customers confidence without slowing growth.

What you’ll take away

  • How “secure enough” changes from product development to market entry to scale.
  • The signs that do-it-yourself security has reached its limit, and where outside or fractional expertise can help.
  • What enterprise buyers look for when they assess a vendor’s security practices.
  • How NIST, CIS Controls, and Zero Trust can become practical decision guides.
  • A way to prioritize the next security move by risk, customer pressure, and business stage.
CIC Cambridge
06 Aug
2026
06:00Ppm - 07:00pm
CIC Cambridge
06 Aug
2026
06:00 PM - 07:00 PM

Who should attend

This session is built for founders, co-founders, CTOs, technical leaders, operators, and other people responsible for growth at startups and small to midsize businesses. No cybersecurity background is required.

From first controls to customer-ready security
Expect a candid conversation about the mistakes growing companies make, the security gaps they tend to overlook, and the point at which informal practices need to become a mature program. Ahrar and Eric will examine what enterprise customers and boards expect, how widely used frameworks can bring order to the work, and how founders can build credibility without treating security as an all-or-nothing project or a compliance checkbox.

Meet the Practitioners

Ahrar Naqvi

CEO, Ebryx

Ahrar leads Ebryx, a global cybersecurity and secure engineering company serving organizations across North America, the Middle East, and Europe. His work spans managed security, advanced R&D, and Zero Trust for critical infrastructure. He previously held senior Engineering roles at Palmchip,Veraz Networks, and Oracle and holds a Master’s Degree in Electrical Engineering from Stanford University.

View linkedin Profile

Eric Galis

CISO, Sun Gauge | Founder & Principal, Plaintext Security Advisors LLC

Eric is a cybersecurity practitioner with hands-on leadership and deep boardroom experience. His work helps growing organizations turn security risk, buyer expectations, and compliance pressure into practical priorities.

View linkedin Profile

Nicole Hart

CEO |Board Advisor| Executive Transformational HR Leader| On-Demand HR and Project-Based Support for Small Businesses

Nicole Hart is co-founder of BackPocket Talent, where she helps small medical practices and founder-led businesses build practical, compliant people systems that can scale. She brings 20 years of experience across HR, operations, and technical leadership. Previously, Nicole led IT, cybersecurity, and compliance at Teracloud, overseeing security operations, risk reduction, and regulatory alignment. She is known for turning complex technical and regulatory requirements into clear actions small teams can execute.

View linkedin Profile

Elijah Cedeno

Member Experience & Engagement Manager

Elijah Cedeno is a Member Experience and Engagement Manager for the Multi-State Information Sharing and Analysis Center™ (MS-ISAC®), a division of the Center for Internet Security, Inc.®. He is a member of the Stakeholder Engagement team, which works with our nation’s State, Local, Territorial, and Tribal (SLTT) governments and public education institutions to provide free cybersecurity resources and services. Elijah manages the MS-ISAC® members in the Northeast region, supporting their overall cybersecurity posture.

View linkedin Profile

Enterprise expertise, scaled to growing companies

Ebryx is a 360° cybersecurity and secure engineering company that helps organizations strengthen defenses, meet compliance expectations, and grow with confidence. For startups and SMBs, Ebryx aligns security to business stage, from essential cyber hygiene and fractional leadership to Zero Trust, managed detection and response, and advanced engineering.

Know what to fix now and what can wait

Join us at CIC Cambridge for a practical hour built around the security
decisions founders actually face.