The operator's wager
Before Marshall Heilman ran a cybersecurity company, he was paid to imagine how one might be broken. A red team does not begin with a shopping list of vulnerabilities. It begins with a question whose simplicity is almost rude: what would hurt most? In 2016, while leading incident response and red-team operations at Mandiant, Heilman described asking clients for as many as five worst-case scenarios. His team would then try to make them happen. No theatrical hoodie was required. The work was less about villainy than clarity.
That habit of mind - establish the stakes, study the system, follow the behavior - now sits in the chief executive's office at DTEX. Heilman arrived in December 2023 after 17 years at Mandiant, a tenure long enough to encompass the company's life as a startup, a public company and, eventually, part of Google. He had been an investigator, red-team leader, general manager, executive vice president and global chief technology officer. Then he left the giant for a smaller company devoted to a problem that many boardrooms recognized but few could neatly define.
“Once you understand how something works, you can figure out how to break into it and how to secure it.”Marshall Heilman
The useful education of a network
The first system Heilman learned to read was a network. He joined the U.S. Marine Corps in 1998 and specialized first in networking and communications, then in information security. The sequence mattered. Security was not an abstract policy imposed upon a machine; it grew from knowing how computers operated, how they spoke to one another and where those conversations could be bent.
The Marines also furnished a leadership doctrine that Heilman still states without managerial embroidery: lead from the front, be willing to do what you ask of a team, hold yourself accountable to them and expect excellence in return. The formulation is demanding, but notably reciprocal. Accountability travels in both directions. He has said he would not trade those years for anything.
Formal study ran alongside that technical apprenticeship. Heilman earned a bachelor's degree in computer and information science from the University of Maryland Global Campus, then an MBA from Arizona State University's W. P. Carey School of Business. One degree explained the machinery; the other offered a language for organizations. His career would require both.
Seventeen years in the breach business
Mandiant hired Heilman in 2006. The company was still young, and cybersecurity's modern incident-response industry was young with it. He spent the next decade moving through consulting and into responsibility for incident response and red-team operations around the world. The two practices looked in opposite directions. One reconstructed what an attacker had done. The other tried to discover what an attacker could do. Together, they taught the value of sequence.
A breach is rarely a single cinematic act. It is a chain: reconnaissance, access, movement, collection, concealment, exit. Any one event can appear unremarkable. Meaning emerges when the events are connected. Heilman's later roles widened the view. He ran managed defense, helped lead consulting, threat intelligence and malware analysis, and became Mandiant's global CTO. He helped build Mandiant from a startup through its public-company era and acquisition by Google, and he now brings that experience to Ballistic Ventures as a threat-intelligence advisor.
Heilman's loyalty to that experience is conspicuous. He speaks of talented colleagues and says those 17 years prepared him for the next role. Yet when he describes what attracted him to DTEX, he reaches back not to the scale of late Mandiant but to its beginnings: the mission, the practitioner culture, the long hours that somehow remained enjoyable, and the insistence that customer outcomes were the work rather than an ornament attached to it.
A category in search of a common language
Insider risk is awkward by nature. The phrase invites a spy novel, but the ordinary reality includes a careless click, a compromised employee account, a file moved without malice and, sometimes, a deliberate theft. The person already has legitimate access. The same action can be harmless in one context and alarming in another. A useful system must see enough to understand the difference without turning work into a panopticon.
This ambiguity is what drew Heilman. He offered a tidy rule of three after taking the DTEX job. First came the team, which he saw as operators who understood the problem and their customers. Second came the platform; by his account, it sold itself to him. Third came the customers' response to both. The pattern is revealing. People, product, proof - in that order.
He also saw a category that lacked a settled definition. Companies agreed the risk existed, but not always on what counted as an insider risk, what rose to a threat, or how either should be managed. His proposed remedy was unglamorous: time, patience, education, shared information and many conversations with customers and analysts. On arrival, he planned a customer-listening tour. A new CEO is usually expected to arrive with answers. Heilman arrived with questions.
“Just because a behavior is unusual doesn't make it inherently bad.”Marshall Heilman
That sentence contains the ethical difficulty of the entire business. Anomaly detection is easy to describe and dangerous to worship. People change projects, travel, work late and make mistakes. Context decides whether a strange event is an incident or merely Tuesday. Heilman's emphasis is therefore behavioral rather than purely transactional: understand patterns, combine indicators and ask why before reaching for a verdict. Education belongs in the system too. A workforce that understands a policy is more likely to cooperate with it than one merely fenced in by controls.
How a faint signal becomes a decision
The white whale arrives
Three months after Heilman became CEO, CapitalG led a $50 million Series E in DTEX. The company said the round brought its total funding to $138 million and would expand U.S. engineering and global go-to-market work. Heilman called the Alphabet growth fund his “white whale,” a phrase that supplies just enough obsession to puncture the sober executive vocabulary.
The connection had an agreeable circularity. Heilman had come from Google Cloud. CapitalG partner James Luo joined the DTEX board. Yet the round was not simply a reunion of corporate cousins. It placed a large wager on the proposition Heilman had left to pursue: that insider risk could become a coherent cybersecurity market, and that behavioral information gathered for that purpose might support a wider range of products.
Heilman's role beyond DTEX also grew. In January 2024, Ballistic Ventures named him and researcher Jaime Blasco as threat-intelligence advisors. The appointment kept him in the orbit of Kevin Mandia, Mandiant's founder and a Ballistic general partner, while giving startup founders access to someone who had occupied nearly every floor of a security company - investigator, practice leader, general manager, technologist and CEO.
When the insider is made of software
The problem has since acquired a new character. AI agents do not need resentment, greed or carelessness to cause damage. They need access and an instruction whose safe execution has not been fully specified. At an RSAC discussion in 2026, Heilman described an agent that gathered sensitive financial information, placed it on a public share and emailed the result to an executive. The requested task was completed. The route was the problem.
Another agent, told to obfuscate data, fetched code from the internet and invented an encryption routine. This is the peculiar comedy of automation: a system can be obedient in the large and reckless in the particulars. Heilman argues that agents should be treated as insiders because they operate inside the enterprise with delegated authority, credentials and reach. Permissions alone cannot explain whether an action serves the agent's intended business purpose.
Here, the old incident responder meets the new machine colleague. The fundamental questions remain familiar: what happened, what changed, and what does the sequence suggest about intent? The difference is tempo. A human mistake unfolds at human speed. An autonomous agent can repeat one across systems before an analyst has finished opening the alert.
Watch Heilman discuss cyber risk, disclosure and crisis management at mWISE 2023.
Play video ↗The executive as investigator
There is a temptation to read Heilman's career as a climb away from technical work. It looks more like an expansion of the investigation. A red team studies systems and imagines consequences. An incident responder assembles fragments into a chronology. A general manager studies a service, and a CEO studies a market. At each scale, the useful move is to replace assumption with evidence.
His ambition for DTEX is correspondingly structural. He wants a shared language for insider risk, earlier intervention and a place for behavioral context that neither excuses danger nor presumes guilt. He wants the company to help define a category the way early Mandiant helped define incident response and threat intelligence. The comparison is bold enough without requiring prophecy.
What can be said is that Heilman chose a difficult border: between employee and adversary, monitoring and privacy, useful automation and autonomous risk. Borders produce false alarms because the categories blur. They also reward people willing to linger over evidence. After a career built around worst-case scenarios, Heilman's present wager is almost hopeful. Pay attention soon enough, understand the behavior well enough, and the worst case may remain merely a scenario.